Researchers from Hacktron AI used Anthropic's Claude model to exploit vulnerabilities and gain access to OpenAI employee accounts, leading to a $6,500 bug bounty reward.
Key facts
- •Researchers used Anthropic's Claude Opus 5 model to generate an exploit script for a heap buffer overflow vulnerability.
- •The breach began on July 25 through OpenAI’s community forum, which utilizes Discourse.
- •The researchers gained access to an OpenAI employee's account, which was linked to the company's GitHub organization.
- •OpenAI addressed the issue by revoking affected sessions and narrowing permissions on community sign-in tokens.
- •The researchers were awarded $6,500 via OpenAI's bug bounty program for their disclosure.
Security researchers from Hacktron AI successfully accessed OpenAI employee accounts by chaining two vulnerabilities, using Anthropic's Claude AI to assist in the exploit. The team gained entry through OpenAI's community forum and demonstrated the ability to reach an internal repository. OpenAI confirmed the incident, stating they have since narrowed permissions on sign-in tokens and revoked affected sessions.
By the numbers
Exploit Methodology and Timeline
The researchers, identified as Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, initiated the breach on July 25 via OpenAI's community forum, which runs on Discourse. They identified a heap buffer overflow flaw in the libheif library. While an initial attempt to develop a remote code execution attack using Claude Opus 4.8 was unsuccessful, the team successfully generated an exploit script using the newer Claude Opus 5 model. The entire process, from discovery to accessing the repository, took less than 72 hours.
Impact and Resolution
By compromising an OpenAI employee's account, the researchers gained access to systems connected to the employee's Codex account, which included potential links to GitHub, Slack, and email services. To prove the impact, they prompted the compromised account to open a pull request in an internal repository but stopped before accessing any internal code. OpenAI paid the researchers a $6,500 bounty through its Bugcrowd program for reporting the vulnerability.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by CBS News Technology, The Register.


