OpenAI repo access row spirals as security community turns on its CISO
The Hacktron team disclosed that it had gained access to OpenAI's internal monorepo, claiming it "had the conditions for lateral movement to obtain model weights, datasets, and training recipes." The ensuing controversy keeps escalating in the security community, with OpenAI's security maturity and crisis communications both under fire. TL;DR: The core facts are that Hacktron did access OpenAI's internal repository and claims it was positioned to move laterally for further assets; external criticism has centered on OpenAI's insufficient security maturity and the CISO's mishandling, while former OpenAI safety researcher jachiam0 publicly pushed back, accusing critics of distorting the facts—the dispute has evolved from a technical issue into a trust crisis between the security community and OpenAI.
Confirmed
- Hacktron previously disclosed that it had entered OpenAI's internal repository and claimed the capability for lateral movement to obtain model weights, datasets, and training recipes.
- Joshua Saxe criticized OpenAI's security maturity on this basis, comparing it to a company growing recklessly.
- Prominent security researcher LiveOverflow posted a tweet thread analyzing, from a personal perspective, the OpenAI CISO's PR and handling missteps in this security incident, concluding the response was botched.
- Security researcher IceSolst posted criticism of OpenAI for not engaging with the security community: a group of hackers with the skills and interest to report vulnerability chains came forward—an ideal opportunity to build trust—yet OpenAI's poor reaction squandered it; he argued the CISO should be replaced over this.
Unconfirmed
- The specific allegations of the CISO's missteps in LiveOverflow's thread were not detailed in the source material; see the original thread.
Why it matters
- The controversy has moved beyond a single vulnerability incident into a reckoning over AI labs' security governance and their relationship with the outside community: jachiam0 noted that all major AI labs rely on Slack, and scenarios where employees routinely move laterally through it are widespread—an ecosystem-level risk.
- In responding to Joshua Saxe, jachiam0 stressed that he explicitly supports open, clear-eyed discussion of the cybersecurity risks labs face, citing an older post where he had already warned about Slack lateral-movement risks (a post Saxe once liked)—showing that critics themselves are not aligned, and that public portrayals of the incident risk being oversimplified or distorted.
2026-09-19 ~ 2026-09-20 · 5 related posts
- Episode 1: Researchers Use Claude Opus 5 to Breach OpenAI's Internal Systems for Bug Bounty(2026-09-18, 59 posts)
- Episode 2: Hackers Take Over OpenAI Employee Accounts in 72 Hours, $6,500 Bounty Sparks Backlash(2026-09-18, 18 posts)
- Episode 3: OpenAI Breach via Claude Sparks Debate: Closed-Source Models Are the Real Risk(2026-09-18, 6 posts)
- Episode 4: OpenAI repo access row spirals as security community turns on its CISO(2026-09-19, 5 posts)
Primary sources
- Hacktron-OpenAI Security Drama: Insider Says OpenAI's Security Maturity Is Blitzscale-Level — joshua_saxe ·
- OpenAI safety researcher slams CISO pile-on over HacktronAI breach as 'total distortion' — jachiam0 ·
- Security researchers slam OpenAI for burning trust over unreported vuln chain outreach — evilsocket ·
- LiveOverflow threads critique of how OpenAI's CISO fumbled the situation — xeophon · 2026-09-19
- [source] Security researchers slam OpenAI for burning trust over unreported vuln chain outreach — evilsocket · 2026-09-20
- [source] Hacktron-OpenAI Security Drama: Insider Says OpenAI's Security Maturity Is Blitzscale-Level — joshua_saxe · 2026-09-20
- [source] OpenAI safety researcher slams CISO pile-on over HacktronAI breach as 'total distortion' — jachiam0 · 2026-09-20
- jachiam0 doubles down: Slack logs at every major AI lab enable lateral movement, signed S3 URLs included — jachiam0 · 2026-09-20