Security researchers used Claude to help them hack into OpenAI
Three independent security researchers at Hacktron say they used Anthropic’s Claude Opus 4.8 and 5 to breach OpenAI employee accounts and access the company’s GitHub repository known as Monorepo in under 72 hours, The Wall Street Journal reports. They exploited a vulnerability in the Discourse forum platform’s HEIF image processing to achieve remote code execution, then demonstrated access by submitting a pull request from an employee Codex account.

Why It Matters
The incident illustrates how advanced generative AI tools can be incorporated into rapid vulnerability research and exploitation, and highlights risks around third-party services that integrate image-processing components into authentication or community software.
Key Facts
- Research team: Three independent security researchers at Hacktron
- AI tools used: Anthropic's Claude Opus 4.8 and 5
- Time to breach: Less than 72 hours
- Target accessed: OpenAI employee accounts and GitHub repository 'Monorepo' (access demonstrated via pull request)
- Vulnerability exploited: HEIF image processing issue in Discourse (third-party forum host)
A trio of independent researchers affiliated with Hacktron reported to The Wall Street Journal that they used Anthropic’s Claude Opus models (versions 4.8 and 5) to penetrate OpenAI employee accounts and reach the company’s GitHub Monorepo in under three days. According to the account, the team did not directly retrieve internal source code from Monorepo but proved they had access by submitting a pull request using an employee Codex account.
The researchers say they achieved an initial foothold by exploiting a flaw in Discourse, the third-party service that runs OpenAI’s community forums. The weakness involved the system Discourse uses to process HEIF images; using that vector, Hacktron reports they obtained remote code execution on Discourse Cloud and used it to reach OpenAI’s instance. Hacktron said Claude Opus 5 launched the evening of July 24, and by 10 a.m. the following day they had leveraged it to obtain RCE on Discourse Cloud.
Hacktron describes the effort as their “HEIF Heist” project and says it was quick to adapt to multiple targets, including Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others. They report conducting the work with less than $3,000 in model tokens and say, to their knowledge, only Shopify detected the activity. The researchers disclosed the vulnerabilities to Discourse and OpenAI, and the issues have since been patched.
OpenAI reportedly paid Hacktron $6,500 for the bug. Hacktron CTO Mohan Pedhapati told the WSJ the team does not see itself on par with nation-state actors, saying, “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.”
Keep Reading

Researchers used Claude to hack OpenAI

US government website used Chinese model the FBI called "malicious"

FAA tees up $875M AI tool to help manage air traffic congestion
