Hackers chained a heap overflow and SSO flaw to breach OpenAI employee accounts in 72 hours

ccerrato147 · x · 2026-09-18

Security team Hacktron AI disclosed that on July 25 they compromised OpenAI internal systems in under 72 hours via a two-vulnerability chain:

The researchers stress they avoided reading sensitive data, coordinated disclosure with OpenAI and Discourse, and published a full technical write-up. The poster mocks OpenAI's stance of lecturing the world on AI security while its own defenses fell.

Related event: White-hat team hijacked OpenAI employee accounts in 72 hours, sparking bounty backlash(10 posts)→

Original post →

More from Safety

Safety channel →