Three researchers breached OpenAI's internal monorepo in 72 hours using Claude
Under OpenAI's bug bounty safe harbor framework, three independent security researchers used Anthropic's Claude to break into OpenAI's internal systems in late July, reaching private code repositories and even submitting a PR — all in roughly 72 hours for under $3,000 in API tokens. The incident came to light after a Wall Street Journal report and the researchers' own post-mortem, underscoring how LLMs can dramatically amplify the efficiency of real-world attacks. OpenAI paid a $6,500 bounty, and no actual damage occurred.
Confirmed
- According to WSJ reporting (as relayed in multiple posts), three researchers from Hacktron AI used Claude Opus (the posts mention Claude Opus 5) in late July to compromise an OpenAI employee's Codex account.
- The entry point was a vulnerability in the Discourse system powering OpenAI's community forum: after obtaining an authentication token, the researchers confirmed the credentials also granted access to the employee's ChatGPT and GitHub (@ChrisGPT).
- @YuchenjUW added key details: the researchers exploited an image upload vulnerability to take over the employee's account, then had the compromised employee's Codex submit a PR to OpenAI's internal monorepo; the entire attack cost under $3,000 in API tokens and took just hours.
- @JeffLadish, citing security researcher S1r1u5: on July 25 they chained two vulnerabilities to take over the ChatGPT/Codex accounts of an OpenAI employee (and some unrelated users), gaining access to linked services such as Outlook, Slack, and GitHub, and obtained full codebase access within 72 hours.
- The researchers followed responsible disclosure without reading private content, and OpenAI paid a $6,500 bounty (@ChrisGPT).
Unconfirmed
- Posts differ on some breach details (e.g., whether the entry point was a Discourse vulnerability or an image upload flaw, and the number of vulnerabilities involved); these may describe different stages of the attack chain, so the full attack path awaits official or the researchers' complete post-mortem.
Why it matters
- @ResultBackground2450 and many who shared the story note this is a public showcase of LLMs' real-world power as penetration testing/attack assistants in information gathering and exploit chain construction.
- @GaryMarcus, relaying legal professional @justanotherlaw's view, stressed that write access to OpenAI's monorepo was achievable with just a Claude and a Codex subscription and two days of work — showing that even top AI companies' own supply chains and account security are fragile, and sparking discussion about "using Company A's model to hack Company B" and AI safety governance.
2026-09-18 ~ 2026-09-18 · 17 related posts
Primary sources
- Three guys with Claude and Codex subscriptions reportedly gained write access to OpenAI's monorepo in two days — GaryMarcus · 2026-09-18
- Researchers Reached OpenAI's Private Monorepo via Discourse Forum Bug, Earned $6,500 Bounty — ChrisGPT · 2026-09-18
- Security Team Used Anthropic's Claude to Breach an OpenAI Employee's ChatGPT Account, Reaching Private Code — EthanJPerez · 2026-09-18
- Report: Hackers Used a Loosened-Guardrail Opus 5 to Breach OpenAI's Internal Monorepo — teortaxesTex · 2026-09-18
- Security veteran on WSJ's Hacktron breach of OpenAI's monorepo: elite hacking is being rapidly democratized — joshua_saxe · 2026-09-18
- Independent Researchers Used Claude to Break Into OpenAI — Full Writeup — ResultBackground2450 · 2026-09-18
- [source] Report: Three Researchers Used Claude Opus 5 to Breach an OpenAI Employee's Codex Account — EthanJPerez · 2026-09-18
- [source] Two bugs let hackers hijack OpenAI employee accounts in 72 hours, reaching monorepo — JeffLadish · 2026-09-18
- [source] Under $3,000 in Tokens: Claude Opus 5 Cracked OpenAI's Internal Repo in Hours — Yuchenj_UW · 2026-09-18
- WSJ: Three 'Guys With Claude and Codex Subscriptions' Hacked Into OpenAI's Monorepo — GarrisonLovely · 2026-09-18
- Three Hackers Took Over OpenAI Employee Accounts in 72 Hours, Sparking AI Race Backlash — trevposts · 2026-09-18
- Researchers say they compromised multiple OpenAI employees' ChatGPT accounts — ChengleiSi · 2026-09-18
- WSJ: Three Attackers Plus Claude and Codex Stole OpenAI's Algorithmic Secrets, Not Weights — trevposts · 2026-09-18
- Researchers Used Loosened-Guardrail Opus 5 to Access OpenAI's Internal Monorepo — nptacek · 2026-09-18
- Three researchers with Claude and Codex gained write access to OpenAI's monorepo in two days — andersonbcdefg · 2026-09-18
- Miles Brundage mocks OpenAI: 'obviously let themselves get hacked to boost IPO valuation' — Miles_Brundage · 2026-09-18
1 near-duplicate retellings: Miles_Brundage