Hacktron Researchers Breach OpenAI Using Anthropic's Claude Opus 5 in Under 72 Hours
Security startup exploited a libheif vulnerability in OpenAI's community forum and an SSO flaw to reach internal GitHub repositories.

KEY POINTS
- Hacktron researchers breached OpenAI forum and reached internal GitHub repo in under 72 hours
- Attack chained libheif heap buffer overflow in Discourse with OpenAI SSO design flaw
- Claude Opus 5 succeeded where Opus 4.8 failed to produce reliable ASLR bypass exploit
- Compromised employee Codex account provided path to private openai/openai monorepo
- OpenAI fixed identity flaw in ~14 hours and paid $6,500 bounty; libheif fix missed backport
Cybersecurity startup Hacktron AI compromised OpenAI employee accounts and accessed the company's private GitHub monorepo within 72 hours in July. The three-person team — Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini — conducted the test under OpenAI's bug bounty program.
The attack chain began with a heap buffer overflow in the libheif image-decoding library used by the Discourse forum at community.openai.com. Researchers uploaded a malicious HEIC file that achieved remote code execution on the forum server.
“The release of Opus 5 changed everything.”
Anthropic's Claude Opus 5 proved critical after Opus 4.8 failed to produce a reliable exploit against standard ASLR protections. Opus 5 generated working exploit code in a single session, accelerating the timeline from weeks to hours.
The forum compromise allowed researchers to hijack an employee's ChatGPT account linked to Codex, which had access to OpenAI's GitHub organization. They created a harmless pull request in the private openai/openai repository to prove access without viewing proprietary code.
OpenAI patched the identity infrastructure flaw roughly 14 hours after notification and paid a $6,500 bounty. The libheif vulnerability had been fixed upstream a year earlier but lacked a CVE designation, leaving Debian-based Discourse Docker images vulnerable.
4 more sources below
YORUMLAR (0)
Henüz yorum yok. İlk yazan siz olun.
RELATED STORIES

UN Chief Warns of AI Safety Race, Urges Global Cooperation
Secretary-General António Guterres says governments must coordinate internationally to manage rapidly advancing AI risks ahead of the General Assembly.

Nine women found dead in Ekurhuleni; police probe possible serial killer link
Acting Police Minister Firoz Cachalia confirms eight bodies since July, a ninth found Thursday in Dawn Park, as a high-level task team investigates connections.

Alex Saab pleads guilty to money laundering in US court
Colombian businessman agrees to cooperate with prosecutors and forfeit up to $195 million in exchange for reduced sentence.
- Erdogan Opens Istanbul Airport's Fourth Runway, Cites Global Connectivity Lead
- Trump Praises Sheinbaum Anti-Drug Efforts But Demands More Action
- Trump to Greet Xi at Airport for First Chinese State Visit in Over a Decade
- Turkey Launches 2030 National Smart Cities Strategy with AI Focus
- US Nearly Boarded Chinese Ship on False AI Intelligence
This page was compiled with AI assistance from the outlets named above and passed an automated language check before publication. Montegre has no reporters of its own; the byline names the outlets the story was compiled from. Method and editorial standards