Hacktron researchers said OpenAI asked them to remove a screenshot proving access to an employee’s account from their disclosure report, and that its chief information security officer called the draft a “stunt document.” Security researcher LiveOverflow later reported an apology: “CISO reached out and apologized 🙇 we are good.”
OpenAI paid the researchers a $6,500 bounty, but Hacktron researcher S1r1u5_ said the payment was not the issue. “the disclosure process itself was nightmarish, we had to get input from lawyers and eventually go to journalist,” the researcher said. OpenAI also asked the team to remove its name from the report’s title and drop a link, the researchers said. LiveOverflow said the public criticism was a personal opinion, not part of the disclosure plan.
The dispute followed Hacktron’s July 25 breach using Anthropic’s Claude. Three researchers chained an image decoder vulnerability in OpenAI’s community forum with a login flaw to take over employee ChatGPT and Codex accounts in less than 72 hours. They demonstrated access by having Codex submit a harmless proposed code change to OpenAI’s private repository. OpenAI fixed the login flaw roughly 14 hours after t
Key sources
- SUPPORT@intcyberdigest“The screenshot showed a pull request Hacktron had Codex open in OpenAI's internal monorepo, to prove they had taken over an employee's account.”x.com
- SOURCE@s1r1u5_“you’re all riling up over the $6,500. that wasn’t even an issue for us. the disclosure process itself was nightmarish, we had to get input from lawyers and eventually go to journalist”x.com
- SOURCE@s1r1u5_“our main incentive for independent security research is to publish the work. if companies pay bounties, great. if they don’t, that’s fine too.”x.com
- SUPPORT@s1r1u5_“CISO reached out and apologized 🙇 we are good.”x.com
- SUPPORT@jachiam0“Thank you for your service of doing white hat hacking and disclosing vulnerabilities privately. Genuinely a good and important service for the ecosystem, for OpenAI, and for the world. This work was hugely helpful.”x.com
- SUPPORT@mlstreettalk“OpenAI has talked a big game about AI for cyberdefense.”x.com
- SUPPORT@xlr8harder“Security experts have been telling OpenAI that their security is negligent for years.”x.com
- SOURCEmarketbrief.now