OpenAI employee ChatGPT and Codex accounts reportedly breached using two bugs
Hacktron’s founder says the team reached connected services including Outlook, Slack and GitHub, and demonstrated access with a pull request in OpenAI’s internal codebase.
TLDR
In a September 18 disclosure, Hacktron’s founder said two bugs let the team take over ChatGPT/Codex accounts belonging to OpenAI employees and some unaffiliated users on July 25. The founder said the attack reached connected services and was demonstrated with a pull request—a proposed code change—in OpenAI’s internal codebase, taking less than 72 hours. The team disclosing “HEIF Heist” also claimed its months-long investigation into libheif, an image library, enabled hacks of OpenAI, Slack, Meta and other targets. SemiAnalysis criticized what it described as a $6,500 bounty from OpenAI as too low for the reported breach.
Combined views
309K
2 Sources, first seen ago

