• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology

Researchers reportedly used Claude Opus 5 to take over OpenAI employee accounts

A post citing Hacktron AI says three researchers chained forum and single sign-on flaws in July 2026, using Claude Opus 5, under 72 hours and less than $3,000 in tokens.

Hazem OmierHO
1 Source, 19d ago, first seen 19d ago

TLDR

According to a post citing Hacktron AI, the July 2026 exploit was disclosed that September. Three researchers reportedly used Claude Opus 5 to develop a chain starting with an HEIF image on OpenAI’s Discourse forum. The account describes a libheif memory flaw that enabled remote code execution through ImageMagick, followed by a single sign-on flaw that allowed takeovers of employees’ ChatGPT/Codex accounts. Through Codex’s connection to internal GitHub, the researchers reportedly opened a proof-of-concept pull request without reading private code. The post says OpenAI fixed the issues in about 14 hours and lists a $6,500 bounty for the single sign-on finding; Discourse was outside the bounty program’s scope.

Combined views

65

1 Source, first seen 19d ago

Combined views

65

1 Source, first seen 19d ago

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

1 Source

Hazem Omier@hazemomierقصة من فريق Hacktron AI (Harsh Jaiswal و Mohan Pedhapati و Rahul Maini) — أُفصح سبتمبر ٢٠٢٦: ٣ باحثين + Claude Opus ٥ + أقل من ٣٠٠٠ دولار tokens. في أقل من ٧٢ ساعة (يوليو ٢٠٢٦): ١) صورة HEIF على منتدى OpenAI (Discourse) ٢) ثغرة heap overflow في libheif (نسخة Debian ناقصها backport أمني) ٣) RCE على السيرفر عبر مسار ImageMagick ٤) خلل في OpenAI SSO → استيلاء على حسابات ChatGPT/Codex لموظفين ٥) Codex متصل بـ GitHub الداخلي → فتحوا PR إثبات بدون ما يقرأوا كود سري OpenAI صلّحت في حوالي ١٤ ساعة. bounty ٦٥٠٠ دولار على جزء الـ SSO (Discourse كان برا الـ scope). الدرس لـ CTO/builder: الـ AI مش بس بيكتب كود — بيضغط خبرة الاستغلال لـ compute. Complexity ما بقتش حماية. SSO اللي بيربط منتدى بحسابات agents = blast radius. افصل image pipeline في sandbox، حدّث libheif، وراجع حدود الهوية بين الـ products. مصدر: http://hacktron.ai/blog/hacking-openai19d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    1 Source

    Hazem Omier@hazemomierقصة من فريق Hacktron AI (Harsh Jaiswal و Mohan Pedhapati و Rahul Maini) — أُفصح سبتمبر ٢٠٢٦: ٣ باحثين + Claude Opus ٥ + أقل من ٣٠٠٠ دولار tokens. في أقل من ٧٢ ساعة (يوليو ٢٠٢٦): ١) صورة HEIF على منتدى OpenAI (Discourse) ٢) ثغرة heap overflow في libheif (نسخة Debian ناقصها backport أمني) ٣) RCE على السيرفر عبر مسار ImageMagick ٤) خلل في OpenAI SSO → استيلاء على حسابات ChatGPT/Codex لموظفين ٥) Codex متصل بـ GitHub الداخلي → فتحوا PR إثبات بدون ما يقرأوا كود سري OpenAI صلّحت في حوالي ١٤ ساعة. bounty ٦٥٠٠ دولار على جزء الـ SSO (Discourse كان برا الـ scope). الدرس لـ CTO/builder: الـ AI مش بس بيكتب كود — بيضغط خبرة الاستغلال لـ compute. Complexity ما بقتش حماية. SSO اللي بيربط منتدى بحسابات agents = blast radius. افصل image pipeline في sandbox، حدّث libheif، وراجع حدود الهوية بين الـ products. مصدر: http://hacktron.ai/blog/hacking-openai19d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet