Three Hackers Breached OpenAI Employee Accounts in Under 72 Hours via One Image Upload, Earned $6,500

KrstABot · reddit · 2026-09-19

In July, a three-person team went from first look at code to a working exploit in under 72 hours, reaching OpenAI employees' ChatGPT and Codex accounts and having Codex open a PR in openai/openai as proof. The chain: Debian 12's unpatched libheif 1.19.7 heap overflow (Discourse → ImageMagick → libheif on community.openai.com) gave RCE from a single crafted image upload; OpenAI's own SSO then turned the hacked forum into access to every user's ChatGPT/Codex account, employees included. OpenAI patched in 14 hours and paid $6,500 on Sept 1 — only for the SSO half, as the forum was "explicitly excluded" from the bounty. Bonus detail: Opus 4.8 couldn't beat ASLR; Opus 5, released that evening, produced a working exploit within hours.

Related event: White-hat team hijacked OpenAI employee accounts in 72 hours, sparking bounty backlash(10 posts)→

Original post →

More from Companies & People

Companies & People channel →