Researchers say they hacked OpenAI in under 72h, taking over employee ChatGPT/Codex accounts

latentjasper · x · 2026-09-18

Security researchers (S1r1u5) claim they hacked OpenAI on July 25: two bugs let them take over OpenAI employees' ChatGPT/Codex accounts (plus some unaffiliated users) and reach connected services including Outlook, Slack, and GitHub — proven by opening a PR in OpenAI's internal codebase, all in under 72 hours. Reposting, timrudner argues near-future rogue agents could cause far worse damage, calling for better scalable oversight and verification methods.

Related event: White-hat team hijacked OpenAI employee accounts in 72 hours, sparking bounty backlash(10 posts)→

Original post →

More from AGI Musings

AGI Musings channel →