Post-Cutoff.com
  1. Home
  2. Timeline
  3. 2026
  4. Three-person startup Hacktron used Claude to break into…

Three-person startup Hacktron used Claude to break into OpenAI's employee accounts and GitHub ($6,500 bug bounty)

★★★after cutoffpolicy-safetyHacktron AIOpenAIAnthropicconfidence: high

On Sept 18, 2026 TechCrunch reported that Hacktron AI, a three-person security startup, used Anthropic's Claude to chain a libheif memory bug in OpenAI's Discourse community forum into a takeover of OpenAI employee ChatGPT and Codex accounts, and from there OpenAI's GitHub organization. The intrusion took under 72 hours in July 2026 and was reported through OpenAI's bug bounty, which paid $6,500. The NYT later reported that OpenAI's CISO had first reacted dismissively.

Key facts

What happened

A small team used a commercially available frontier model to find and chain bugs in OpenAI's own internet-facing systems, then reported them through the official bounty program.

Why it matters

It is a concrete case of AI-assisted offensive security against a frontier lab, and it shows how cheap such attacks had become (a quoted expert: "For $200 a month, anyone can use these tools and hack into a company like OpenAI"). It also became evidence in the NYT's account of how OpenAI handled security warnings.

Changelog

  • 2026-10-01: created (leads run, from the NYT OpenAI-warnings lead)

Related events

  1. NYT: OpenAI repeatedly dismissed employee warnings that its newest models were not adequately monitored or secured during testing ★★★★
  2. Anthropic releases Claude Opus 5 — near-Fable-5 intelligence at half the price ★★★★

Sources (3)

id: 2026-09-18-hacktron-claude-hacks-openai · updated 2026-10-01 · open in the interactive timeline