Hacktron says Claude helped breach OpenAI employee accounts
Hacktron says it paired a Discourse image-processing flaw with an OpenAI identity issue to compromise employee ChatGPT accounts and reach a private code repository before responsibly disclosing the chain.
Hacktron says it compromised multiple OpenAI employee ChatGPT accounts and used one connected Codex account to submit a harmless pull request to an internal code repository. The security company says it did not inspect or download OpenAI code and stopped testing after demonstrating the access path.
The researchers say they carried out the exploit chain on July 25 and reported it through OpenAI’s Bugcrowd program. According to Hacktron, OpenAI confirmed later that day that the company-side issue had been fixed; the company later paid a $6,500 bounty for the finding. OpenAI has not published a first-party incident report in the sources reviewed.
The chain started in the Discourse software hosting OpenAI’s community forum. Hacktron says a malformed HEIF image triggered remote code execution through the forum’s image-processing stack, letting the researchers run code on the server. They paired that access with what they described as a flaw in OpenAI’s single-sign-on identity flow, reaching employee ChatGPT and Codex accounts.
Discourse’s security advisory confirms that CVE-2026-32882 in libheif allowed remote code execution through image uploads. Discourse gave the issue an 8.8 rating, classified it as high severity and credited Hacktron as the reporter. The advisory lists patched releases and says supported versions added image-processing sandboxing as a further defense.
Hacktron says Anthropic’s Claude Opus 4.8 identified missing security backports and produced an initial exploit, while Claude Opus 5 generated a working local exploit. The team says it tested the resulting script on its own Discourse Cloud instance before applying it to OpenAI’s forum. It also says the operation was not fully autonomous and still depended on skilled human guidance.
The researchers say compromised ChatGPT or Codex accounts could theoretically have exposed other connected services, including Slack and email. Their public demonstration established the GitHub path through the harmless pull request, but did not show access to those other services. The number and identities of affected accounts remain undisclosed.
Hacktron argues that AI compressed offensive-security work that once required a well-resourced team and months into days. That comparison remains the company’s assessment: the public evidence does not independently measure the counterfactual staffing, time or cost. The incident is distinct from AI-lab breaches linked to Irregular.
Hacktron says it also reported the Discourse issue through HackerOne. Discourse released patched versions and added sandboxing around image processing; Hacktron says OpenAI confirmed later that day that the identity issue had been fixed, after the researchers had ended their testing.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
