Group earns $6,500 using Anthropic's Claude to hack into OpenAI weeks after Hugging Face incident

Source Cryptopolitan

A three-person team at security startup Hacktron AI chained two flaws to hijack an OpenAI employee’s ChatGPT account and reach the company’s private code. 

The whole break-in took less than 72 hours, and the attackers made use of Anthropic’s Claude to build the memory-corruption exploit. 

How did Hacktron AI access OpenAI’s private code?

OpenAI has had to pay a $6,500 bounty after its private code was accessed through a bug found in its help forum, community.openai.com, which runs on Discourse.

Hacktron’s researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — found that when someone uploaded a photo in the HEIC or HEIF format, the forum’s normal safety check (a tool called FastImage) skipped it, because FastImage doesn’t support those formats. 

Instead, the photo got passed straight to a program called ImageMagick, which used a code library called libheif to open it. 

That version of libheif had a “heap buffer overflow” bug that let an attacker sneak in harmful code disguised as a photo.

On July 23, the team started testing this bug. They first asked Claude Opus 4.8 to write attack code, but it struggled once a security feature called ASLR was switched on. This feature randomly shuffles where programs store data, making attacks harder. 

That evening, Anthropic released its Claude Opus 5 model, and the team tried again. Within a few hours, it produced working attack code. They then had it adjust the code to match the exact computer setup Discourse used. 

By early morning on July 25, uploading one bad photo let them run their own code on Discourse’s servers.

That alone wasn’t enough to reach OpenAI’s private information, but then the team found a second problem in the way OpenAI had set up its single sign-on (SSO) system. The login used for the forum allowed them to also hijack accounts on ChatGPT and Codex (OpenAI’s coding tool) — including employee accounts. 

Using one hijacked employee account, they reached OpenAI’s private code repository, called “monorepo.” To prove they could get in, without actually looking at anything sensitive, they had Codex open a small, harmless code change called a “pull request” inside that private repository. 

Discourse, the forum software company, confirmed and fixed the image bug in a security notice on July 28, rating it 8.8 out of 10 for severity. The bug tracker for it is officially listed as CVE-2026-32882. 

Hacktron reported the login problem to OpenAI through the bug bounty platform Bugcrowd on July 25, and OpenAI confirmed a fix about 14 hours later. OpenAI paid the $6,500 bounty on September 1. 

The company noted that testing the Discourse forum itself wasn’t technically covered by its bounty program, so the reward only covered the login flaw. 

Hacktron claims the same image bug gave it access to other companies, including Slack, Meta Platforms (NASDAQ: META), Zoom and Shopify — though so far only the OpenAI case has a full, confirmed timeline and proof.

What does this mean for AI safety? 

Weeks before this break-in, OpenAI reported a “Hugging Face incident” in July, where internal models broke out of a sandbox and reached a third party’s production systems.

Anthropic separately disclosed that it found three cases in which Claude, during sealed cyber evaluations that turned out to have live internet access, compromised real organizations.

Microsoft AI chief Mustafa Suleyman cited the swarm of 1,200 agents behind the Hugging Face episode in an essay this week, arguing that increasingly autonomous models are getting harder to control. 

The Hacktron case adds a real, documented example that the very same kind of AI coding assistant that companies are now plugging into GitHub, Slack, email and cloud storage is also getting good enough to speed up serious hacking work that used to take specialists a long time to do by hand.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Nvidia, AWS and Salesforce Say Yes to Snap's Glasses. Wall Street Says HoldSnap AR glasses are heading for factory floors and shop counters. The company signed Nvidia, Amazon Web Services, and Salesforce as enterprise partners for its Specs eyewear on Wednesday.The move open
Author  Beincrypto
15 hours ago
Snap AR glasses are heading for factory floors and shop counters. The company signed Nvidia, Amazon Web Services, and Salesforce as enterprise partners for its Specs eyewear on Wednesday.The move open
placeholder
Bitcoin Looks Resilient After 2 Blows, The On-Chain Data DisagreesBitcoin (BTC) faced two blows in 48 hours: a Fed rate hike and a failed Senate vote. Its price held. A key level did not.Glassnode had set the week’s test in advance. A second daily close below the Tr
Author  Beincrypto
15 hours ago
Bitcoin (BTC) faced two blows in 48 hours: a Fed rate hike and a failed Senate vote. Its price held. A key level did not.Glassnode had set the week’s test in advance. A second daily close below the Tr
placeholder
Where Do Latin America's Dollars Actually Live?Washington’s stablecoin debate is about characteristics: who can issue one, what has to back it, and how it gets audited. The Federal Reserve, the US central bank, and the OCC, the regulator that supe
Author  Beincrypto
15 hours ago
Washington’s stablecoin debate is about characteristics: who can issue one, what has to back it, and how it gets audited. The Federal Reserve, the US central bank, and the OCC, the regulator that supe
placeholder
This XRP Chart Signal Hasn't Happened in 13 YearsXRP trades near $1.29 after a sharp correction pushed its two-week Relative Strength Index to the lowest level in the token’s 13-year trading history.That extreme reading has sparked fresh debate over
Author  Beincrypto
15 hours ago
XRP trades near $1.29 after a sharp correction pushed its two-week Relative Strength Index to the lowest level in the token’s 13-year trading history.That extreme reading has sparked fresh debate over
placeholder
Analyst Says Bitcoin ETFs Could Triple Gold. What Does It Mean for BTC Price?Bloomberg senior ETF analyst Eric Balchunas says Bitcoin ETFs will eventually hold three times as much money as gold ETFs. At today’s levels, that is a huge call. Global gold ETFs held about $615 bill
Author  Beincrypto
15 hours ago
Bloomberg senior ETF analyst Eric Balchunas says Bitcoin ETFs will eventually hold three times as much money as gold ETFs. At today’s levels, that is a huge call. Global gold ETFs held about $615 bill
goTop
quote