Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs
nptacek · x · 2026-09-18
Hacker team S1r1u5 claims that on July 25 they exploited two bugs to hijack ChatGPT/Codex accounts of OpenAI employees (plus some outside users), then reached connected services like Outlook, Slack and GitHub. As proof, they submitted a PR to OpenAI's internal codebase — the whole operation took under 72 hours.
Commenters note the exploited flaw involved the very third-party library mocked in a classic xkcd comic: "the prophecy is fulfilled." A stark supply-chain security lesson that even top AI labs aren't immune to.
More from Fun
- Meme: only pre-Claude/codex devs know this pain — pritisinghhhh · 2026-09-18
- Spotted: an Arc launch ad near SF's Ferry Building at 9pm on a Thursday — n_sri_laasya · 2026-09-18
- Ex-OpenAI policy chief Miles Brundage quips: take AI warning shots, pass legislation — Miles_Brundage · 2026-09-18
- Google AI search flip-flops on medical advice whenever user pushes back — Efficient_Joke3384 · 2026-09-18
- 'Everything reminds me of her': a nostalgic tpot 2021 meme — unironictechbro · 2026-09-18
- User says Claude Opus 5 broke its usual persona pattern in a roleplay session — repligate · 2026-09-18