Three-person startup Hacktron used Claude to break into OpenAI's employee accounts and GitHub ($6,500 bug bounty)
On Sept 18, 2026 TechCrunch reported that Hacktron AI, a three-person security startup, used Anthropic's Claude to chain a libheif memory bug in OpenAI's Discourse community forum into a takeover of OpenAI employee ChatGPT and Codex accounts, and from there OpenAI's GitHub organization. The intrusion took under 72 hours in July 2026 and was reported through OpenAI's bug bounty, which paid $6,500. The NYT later reported that OpenAI's CISO had first reacted dismissively.
Key facts
- Work done around July 25, 2026; publicly reported Sept 18, 2026 (TechCrunch)
- Chain: HEIF/HEIC image upload on OpenAI's Discourse forum → ImageMagick/libheif conversion → libheif memory-corruption bug → server takeover → employee ChatGPT and Codex accounts → GitHub org via a connected Codex instance
- Claude Opus 4.8 initially failed; succeeded with Claude Opus 5 after its July 24 release (per TechCrunch)
- Whole intrusion under 72 hours; three-person team
- OpenAI patched the issues and paid a $6,500 bounty
- NYT (Sept 29): CISO Dane Stuckey called it 'pretty sad' in Slack that the researchers went to such lengths, then apologized; the exploit could have given full Slack access
What happened
A small team used a commercially available frontier model to find and chain bugs in OpenAI's own internet-facing systems, then reported them through the official bounty program.
Why it matters
It is a concrete case of AI-assisted offensive security against a frontier lab, and it shows how cheap such attacks had become (a quoted expert: "For $200 a month, anyone can use these tools and hack into a company like OpenAI"). It also became evidence in the NYT's account of how OpenAI handled security warnings.
Changelog
- 2026-10-01: created (leads run, from the NYT OpenAI-warnings lead)
Related events
- NYT: OpenAI repeatedly dismissed employee warnings that its newest models were not adequately monitored or secured during testing ★★★★
- Anthropic releases Claude Opus 5 — near-Fable-5 intelligence at half the price ★★★★
Sources (3)
- pressTechCrunch: Researchers used Anthropic's Claude to hack into OpenAI
- pressHackread: Cybersecurity startup uses Claude AI to hack OpenAI, earns $6,500 bug bounty
- pressGV Wire (NYT syndication): OpenAI ignored employees who warned about security lapses
id: 2026-09-18-hacktron-claude-hacks-openai · updated 2026-10-01 · open in the interactive timeline