Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens. While Claude Opus 4.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens.
OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub.
Key sources
- SOURCE@wsj“gave them a way to read and suggest changes to the company’s private cache of software”x.com
- SOURCE@notdeghost“On July 25, we hacked OpenAI”x.com
- SUPPORT@mtslive“Three researchers at Hacktron AI, operating under OpenAI’s bug-bounty safe harbor, used Claude Opus 5 in late July”x.com
- SOURCE@infosec_au“investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub”x.com
- SUPPORT@rohanpaul_ai“OpenAI said its review found only “limited reads” of private-repository metadata and code changes; no model weights were believed exposed”x.com
- SUPPORT@yuchenj_uw“Their entire hacking cost less than $3000 in tokens”x.com
- SUPPORT@tradfi“OPENAI PAID SECURITY RESEARCHERS A $6,500 BOUNTY FOR UNCOVERING VULNERABILITIES”x.com
- SOURCEmarketbrief.now