Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens. While Claude Opus 4.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens.

OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub.

Sign in to suggest edits

Key sources

  1. SOURCE@wsj“gave them a way to read and suggest changes to the company’s private cache of software”x.com
  2. SOURCE@notdeghost“On July 25, we hacked OpenAI”x.com
  3. SUPPORT@mtslive“Three researchers at Hacktron AI, operating under OpenAI’s bug-bounty safe harbor, used Claude Opus 5 in late July”x.com
  4. SOURCE@infosec_au“investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub”x.com
  5. SUPPORT@rohanpaul_ai“OpenAI said its review found only “limited reads” of private-repository metadata and code changes; no model weights were believed exposed”x.com
  6. SUPPORT@yuchenj_uw“Their entire hacking cost less than $3000 in tokens”x.com
  7. SUPPORT@tradfi“OPENAI PAID SECURITY RESEARCHERS A $6,500 BOUNTY FOR UNCOVERING VULNERABILITIES”x.com
  8. SOURCEmarketbrief.now
Markdown