---
format: "aidr-story-markdown/v1"
id: "e505b133bcd14a2849c9dae97d60f816d47906b03e37e0a1332eb40144dc1a91"
canonical_url: "https://aidr.today/e505b133?lang=en"
title: "Hacktron AI Uses Anthropic Opus 5 to Breach OpenAI Code for $6,500 Bounty"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-19T02:45:58.000Z"
category: "Models"
topics: ["anthropic","claude","multi-agent","open-source","hacktron-ai","openai","security","bounty"]
source_urls: ["https://x.com/rootxharsh/status/2100801820960620574","https://x.com/HacktronAI/status/2100795824812777893","https://x.com/NahamSec/status/2101015019844698338","https://x.com/gauravisnotme/status/2100931755448631682","https://x.com/peterwildeford/status/2101034137469534625","https://x.com/ziv_ravid/status/2100994662857068788","https://x.com/MTSlive/status/2101026237116526794","https://x.com/jachiam0/status/2100934073468199147"]
summary: "Three security researchers from Hacktron AI breached OpenAI's internal code repository in less than 72 hours on July 25 using a chain of two vulnerabilities. The team gained access to ChatGPT and Codex accounts belonging to OpenAI employees, which enabled them to submit a harmless pull request to the company's internal GitHub monorepo. OpenAI paid the researchers a $6,500 bug bounty and patched a single sign-on flaw within 14 hours of the report. The attack exploited a heap overflow in libheif, an image library used by OpenAI's Discourse hosted community forum. Hacktron AI's HEIF Heist investigation identified vulnerabilities in libheif affecting Meta, Slack, and GitHub Enterprise that could lead to remote code execution. The researchers used Anthropic's Claude Opus 5 to produce a working exploit within three hours of the model's release, after the previous Opus 4.8 model failed to do so."
---

# Hacktron AI Uses Anthropic Opus 5 to Breach OpenAI Code for $6,500 Bounty

> [Open the canonical story](<https://aidr.today/e505b133?lang=en>)

**Published:** 2026-09-19T02:45:58.000Z
**Category:** Models
**Topics:** anthropic, claude, multi\-agent, open\-source, hacktron\-ai, openai, security, bounty

## Summary

Three security researchers from Hacktron AI breached OpenAI's internal code repository in less than 72 hours on July 25 using a chain of two vulnerabilities\. The team gained access to ChatGPT and Codex accounts belonging to OpenAI employees, which enabled them to submit a harmless pull request to the company's internal GitHub monorepo\. OpenAI paid the researchers a $6,500 bug bounty and patched a single sign\-on flaw within 14 hours of the report\. The attack exploited a heap overflow in libheif, an image library used by OpenAI's Discourse hosted community forum\. Hacktron AI's HEIF Heist investigation identified vulnerabilities in libheif affecting Meta, Slack, and GitHub Enterprise that could lead to remote code execution\. The researchers used Anthropic's Claude Opus 5 to produce a working exploit within three hours of the model's release, after the previous Opus 4\.8 model failed to do so\.

## Sources

- [Story source](<https://x.com/rootxharsh/status/2100801820960620574>)
- [Supporting source](<https://x.com/HacktronAI/status/2100795824812777893>)
- [Supporting source](<https://x.com/NahamSec/status/2101015019844698338>)
- [Story source](<https://x.com/gauravisnotme/status/2100931755448631682>)
- [Supporting source](<https://x.com/peterwildeford/status/2101034137469534625>)
- [Supporting source](<https://x.com/ziv_ravid/status/2100994662857068788>)
- [Supporting source](<https://x.com/MTSlive/status/2101026237116526794>)
- [Supporting source](<https://x.com/jachiam0/status/2100934073468199147>)

