Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs

nptacek · x · 2026-09-18

Hacker team S1r1u5 claims that on July 25 they exploited two bugs to hijack ChatGPT/Codex accounts of OpenAI employees (plus some outside users), then reached connected services like Outlook, Slack and GitHub. As proof, they submitted a PR to OpenAI's internal codebase — the whole operation took under 72 hours.

Commenters note the exploited flaw involved the very third-party library mocked in a classic xkcd comic: "the prophecy is fulfilled." A stark supply-chain security lesson that even top AI labs aren't immune to.

Original post →

More from Fun

Fun channel →