Two bugs let hackers take over OpenAI employee ChatGPT/Codex accounts in under 72 hours
Miles_Brundage · x · 2026-09-18
Security researcher S1r1u5 discloses that on July 25 two bugs enabled takeover of ChatGPT/Codex accounts belonging to OpenAI employees (plus some external users), reaching connected services like Outlook, Slack, and GitHub — proven with a PR in OpenAI's internal codebase, all in under 72 hours, followed by responsible disclosure. BorisMPower and former OpenAI policy head Miles Brundage amplified the write-up.
Related event: Researchers Used Claude to Breach OpenAI's Internal Codebase(22 posts)→
More from Safety
- Air-gapping is leakier than you think: LED exfil at 100 kbps and dozens of side channels — dioscuri · 2026-09-18
- NHTSA developing federal ADS performance standard as US preps for larger-scale Robotaxi rollouts — Scobleizer · 2026-09-18
- Models fill in blanks: a pre-execution gate that strips verdict authority from LLMs — Jay299792458 · 2026-09-18
- tszzl: Weight self-exfiltration can only be done at the lab, not via side channels — tszzl · 2026-09-18
- That viral "air-gapped data exfiltration" paper only read temperature over a 4cm gap — basedjensen · 2026-09-18
- New paper shows models can fingerprint and exploit inference engines like vLLM using output tokens alone — chaumian · 2026-09-18