In July 2026, security researchers from Hacktron gained access to multiple OpenAI employees' ChatGPT accounts by chaining two vulnerabilities. This breach allowed the team to access OpenAI’s internal repositories, which they demonstrated by opening a pull request in the company's internal monorepo.
Researchers use Claude models to exploit libheif vulnerability and access OpenAI employee accounts
The exploit targeted a remote code execution (RCE) vulnerability in the libheif library. The vulnerability was triggered when the Discourse-hosted community forum (community.openai.com) processed HEIC/HEIF files through ImageMagick. The researchers utilized Anthropic's Claude models to develop and port the exploit, noting that Claude Opus 5 was able to adapt the exploit for an x86-64 environment within hours. They observed that increasing AI capabilities allow small teams to rapidly adapt exploits to specific target environments.
The breach was facilitated by a Single Sign-On (SSO) misconfiguration in OpenAI’s identity infrastructure, which allowed the compromise of the community forum to escalate into access for broader services, including ChatGPT and Codex.
OpenAI has since patched the issue and paid the researchers a $6,500 bounty through its Bug Bounty Program. Discourse also released a patch and implemented additional image-processing sandboxing as a defense-in-depth measure.
Sources
- Hacking OpenAI (Hacker News Frontpage, 2026-09-18)
- GitHub Advisory
2 more sourcesHide sources
- Researchers used Claude to hack OpenAI (Ars Technica AI, 2026-09-18)
- Security researchers used Claude to help them hack into OpenAI (The Verge AI, 2026-09-18)