ThinkPatternGet the app
Story
TECHNOLOGY · SEP 18, 2026

Hacktron AI Breaches OpenAI Codebase Using Claude AI

Hacktron AI researchers used Anthropic's Claude AI to exploit a forum vulnerability and breach OpenAI's internal GitHub repository, resulting in a $6,500 bug bounty.

Researchers from Hacktron AI used Anthropic's Claude Opus 5 model to breach the internal codebase and employee accounts of OpenAI. The operation, which the researchers named HEIF Heist, began by exploiting a buffer overflow vulnerability in libheif, an open-source tool used by Discourse, the third-party platform powering OpenAI's community forum. By using Claude to analyze server data and generate weaponized code, the team achieved remote code execution and leveraged a single sign-on misconfiguration to impersonate an employee.

This access allowed the researchers to enter privileged internal systems, including Slack, email, and a private software repository known as Monorepo. While they gained access to algorithmic secrets and internal GitHub environments, they did not access core model weights. The entire process from initial discovery to repository access took less than 72 hours. Upon confirming the breach by initiating a pull request, the researchers reported the flaws through OpenAI's bug-bounty program.

OpenAI responded by narrowing permissions on community sign-in tokens, revoking affected sessions, and paying Hacktron AI a $6,500 bounty. Both OpenAI and Discourse patched the vulnerabilities within 14 hours of the report. Hacktron AI further noted that the same libheif vulnerability affected Meta Platforms Inc. and Salesforce Inc.'s Slack, warning that the absence of a CVE database entry for the bug series hindered industry-wide detection.


Reported across 53 outlets
Actors
Hacktron AI Inc.OpenAIAnthropicDiscourse

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play