---
format: "aidr-story-markdown/v1"
id: "6a0214cbc102abbd3352382b5aa949f249f837463cfb10d195694e3144139e40"
canonical_url: "https://aidr.today/6a0214cb?lang=en"
title: "Three Researchers Breach OpenAI Monorepo Using Claude Opus 5"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-18T05:50:36.000Z"
category: "Models"
topics: ["anthropic","claude","multi-agent","open-source","openai","monorepo","researchers","security"]
source_urls: ["https://huggingnews.com/cybersecurity/three-researchers-breach-openai-monorepo-using-claude-opus-5-1ac33833","https://x.com/WSJ/status/2100763117827322195","https://x.com/NotDeGhost/status/2100778077714620598","https://x.com/MTSlive/status/2100768872177771001","https://x.com/infosec_au/status/2100809685582631073","https://x.com/rohanpaul_ai/status/2100810101145891305","https://x.com/Yuchenj_UW/status/2100778872728060304","https://x.com/tradfi/status/2100751788622393577"]
summary: "Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens. While Claude Opus 4.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens. OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub."
---

# Three Researchers Breach OpenAI Monorepo Using Claude Opus 5

> [Open the canonical story](<https://aidr.today/6a0214cb?lang=en>)

**Published:** 2026-09-18T05:50:36.000Z
**Category:** Models
**Topics:** anthropic, claude, multi\-agent, open\-source, openai, monorepo, researchers, security

## Summary

Independent security experts from Hacktron AI leveraged Anthropic's Claude Opus 5 to seize OpenAI employee accounts and penetrate the company's private GitHub monorepo on July 25\. The team, operating under OpenAI's bug bounty safe harbor, chained a Discourse flaw and an image upload bug to acquire authentication tokens\. While Claude Opus 4\.8 struggled with the exploit, the Opus 5 model cracked the security within hours, with the total attack cost totaling less than $3,000 in AI tokens\. OpenAI paid the researchers a $6,500 bounty after its subsequent review found only limited reads of private repository metadata and code changes, and no model weights were exposed\. The incident was part of a broader investigation named HEIF Heist into the libheif library, which the researchers claim also enabled them to hack Meta, Slack, and GitHub\.

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/three-researchers-breach-openai-monorepo-using-claude-opus-5-1ac33833>)
- [Story source](<https://x.com/WSJ/status/2100763117827322195>)
- [Story source](<https://x.com/NotDeGhost/status/2100778077714620598>)
- [Supporting source](<https://x.com/MTSlive/status/2100768872177771001>)
- [Story source](<https://x.com/infosec_au/status/2100809685582631073>)
- [Supporting source](<https://x.com/rohanpaul_ai/status/2100810101145891305>)
- [Supporting source](<https://x.com/Yuchenj_UW/status/2100778872728060304>)
- [Supporting source](<https://x.com/tradfi/status/2100751788622393577>)

