White-hat team hijacked OpenAI employee accounts in 72 hours, sparking bounty backlash
On July 25, security team S1r1u5 (also known as Hacktron AI, members include Harsh Jaiswal and others) used two vulnerability chains to take over ChatGPT/Codex accounts of OpenAI employees and some external users in under 72 hours, further reaching connected internal services like Outlook, Slack, and GitHub, and even submitted a PR to an internal code repository to prove the breach. On September 18 the team published a blog post with the details, and the incident sparked wide discussion about OpenAI's security investment and bounty levels.
Confirmed
- Attack chain: the HEIF image upload feature on OpenAI's forum (Discourse) triggered a libheif heap overflow, combined with an OpenAI SSO flaw to achieve account takeover
- OpenAI fixed the SSO vulnerability within about 14 hours of receiving the report; the Discourse vulnerability was reported Saturday, answered Sunday, and fixed Monday
- OpenAI paid a $6,500 bounty for the SSO vulnerability
- The $6,500 only covered the discovery of the OpenAI-side SSO flaw; the Discourse forum hands-on work that demonstrated real-world impact was subsequently clarified by OpenAI as "explicitly excluded" from the bounty scope
Unconfirmed
- Whether the attackers actually accessed model weights, source code, or private communications; OpenAI has not officially confirmed the actual scope of impact in the available material
Why it matters
- @ccerrato147 relayed researchers' view that a ChatGPT account with access to a company's GitHub, Slack, and email is worth several orders of magnitude more than $6,500 on the gray market, potentially yielding model weights, source code, and private communications—the bounty is severely mismatched with the risk
- Researchers also criticized OpenAI for still not taking cybersecurity seriously enough after the incident was exposed; the event laid bare AI giants' weak points in employee accounts and identity authentication chains, serving as a warning for industry security practices
2026-09-18 ~ 2026-09-19 · 10 related posts
Primary sources
- [source] OpenAI Pays $6,500 Bounty, Fixes SSO Bug 14 Hours After Report — teortaxesTex · 2026-09-18
- Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs — nptacek · 2026-09-18
- Researchers say they hacked OpenAI in under 72h, taking over employee ChatGPT/Codex accounts — latentjasper · 2026-09-18
- Researchers Chained Two Bugs to Compromise OpenAI Internal Repos in 72 Hours — banteg · 2026-09-18
- [source] OpenAI's $6,500 bounty covered only the SSO bug; the exploit work was ruled out of scope — ccerrato147 · 2026-09-18
- Researcher slams OpenAI's $6,500 bounty: hacked ChatGPT account worth far more on grey market — ccerrato147 · 2026-09-18
- OpenAI hacked by white hats who reported the bugs, rewarded with just $6,500 bounty — EconomySerious · 2026-09-19
- Three Hackers Breached OpenAI Employee Accounts in Under 72 Hours via One Image Upload, Earned $6,500 — KrstABot · 2026-09-19
2 near-duplicate retellings: ccerrato147 · NathanpmYoung