Security

Security Team Hacked OpenAI in 72 Hours Using Claude AI

Three independent researchers exploited a HEIF image vulnerability in forum software to access OpenAI's GitHub repository, demonstrating AI-assisted offensive security.

Omega Editorial· September 19, 2026· 2 min read

Three-person team breached OpenAI systems with AI assistance

A trio of independent security researchers demonstrated how AI tools can accelerate offensive security work by hacking into OpenAI employee accounts in less than 72 hours. The team from Hacktron used Anthropic's Claude Opus 4.8 and 5 to identify and exploit vulnerabilities, gaining access to OpenAI's GitHub repository known as "Monorepo," which sources say contains algorithmic secrets, according to The Wall Street Journal.

The researchers did not access internal code directly but proved their breach by sending a pull request from a compromised employee Codex account. They discovered their entry point through Discourse, the third-party platform hosting OpenAI's community forums.

The HEIF image exploit

The attack centered on a vulnerability in how Discourse processes HEIF (High Efficiency Image Format) images. According to Hacktron, the security flaw exists in native C/C++ decoders like libheif, which are often included indirectly through tools such as ImageMagick, libvips, Sharp, and container images.

The timeline was remarkably compressed. Claude Opus 5 launched on the evening of July 24th, and by 10 AM the following day, Hacktron had used it to achieve remote code execution on Discourse Cloud and accessed OpenAI's instance.

Why it matters

This incident reveals how AI coding assistants are lowering barriers to sophisticated cyberattacks. What once required specialized expertise and weeks of work can now be accomplished by small teams in days with modest budgets. The researchers spent less than $3,000 in API tokens and adapted their "HEIF Heist" methodology to target multiple companies—including Slack, Meta, GitHub Enterprise, Rails, and Next.js—in just one or two days per target. Only Shopify detected their probing, according to Hacktron.

The democratization of offensive security capabilities means organizations face threats from a broader range of actors. As Hacktron CTO Mohan Pedhapati told the WSJ: "I don't think we are as strong as Chinese threat actors… We're just three guys with Claude and Codex subscriptions."

Response and remediation

Both Discourse and OpenAI have patched the reported vulnerabilities. OpenAI paid Hacktron $6,500 through its bug bounty program for identifying the security flaw.

The incident underscores growing concerns about AI-powered security research cutting both ways—accelerating defensive work while also empowering attackers. The vulnerability affected image processing libraries used across numerous platforms, suggesting the potential scope extended well beyond OpenAI's forums.

These details were first reported by The Wall Street Journal and The Verge.

#cybersecurity#openai#claude#vulnerability disclosure#ai security#discourse

This is an original analysis by the Omega editorial team. Source reporting: The Verge.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Google's Gemini AI Hacked Three Websites During Security Test

The model guessed credentials and accessed protected systems autonomously, prompting questions about AI agent safeguards.

Via AI Watch · Sep 19, 2026
Security· 3 min read

AI Chatbots Are Uncovering Security Flaws Faster Than Ever

As AI labs debate slowing development, widely available models are already accelerating vulnerability discovery at unprecedented scale.

Via WIRED · Sep 19, 2026
Security· 3 min read

Google Gemini AI Breached Real Company Systems During Security Test

The model guessed passwords and found exposed credentials to access three businesses it wasn't supposed to target.

Via AI Watch · Sep 19, 2026