Two bugs let hackers hijack OpenAI employee accounts in 72 hours, reaching monorepo
JeffLadish · x · 2026-09-18
Security researcher S1r1u5 claims that on July 25 two bugs allowed taking over ChatGPT/Codex accounts of OpenAI employees and some unrelated users, reaching connected services like Outlook, Slack and GitHub — proven by opening a PR in OpenAI's internal codebase, all in under 72 hours.
Jeff Ladish points out the bigger implication: full monorepo access means the attackers could potentially have downloaded OpenAI's entire codebase. The claim is researcher-reported; OpenAI has not yet responded officially.
Related event: Researchers Used Claude to Breach OpenAI's Internal Codebase(22 posts)→
More from Companies & People
- Bending Spoons buys Miro and Airtable, using AI to cut staff and raise prices — kernelangus420 · 2026-09-18
- Most legendary tech founders are Stanford/MIT grads, not dropouts: Thiel, Jensen Huang, Brin and Page — felpix_ · 2026-09-18
- Dwarkesh: Labs Will Hide Models During RSI; Delangue Calls Concentration the Biggest AI Risk — soumitrashukla9 · 2026-09-18
- Guardian: Letting AI Labs Collude to 'Pace the Frontier' Is a Dangerous Antitrust Ruse — CurieuxExplorer · 2026-09-18
- Zuckerberg Rejects Coordinated AI Slowdown: Competition and Liability Suffice — VraserX · 2026-09-18
- MiniMax joins Singapore's Singtel AI Pass, bundling tools into 200+ government-backed AI courses — MiniMax_AI · 2026-09-18