Hackers took over OpenAI employee ChatGPT accounts in 72 hours, got ~$6,500 bounty
NathanpmYoung · x · 2026-09-19
Security researchers (S1r1u5) disclosed that on July 25 they chained two bugs to take over ChatGPT/Codex accounts of OpenAI employees and unaffiliated users, reaching connected services like Outlook, Slack, and GitHub — proven via a PR in OpenAI's internal codebase, in under 72 hours. Reposting, tracewoodgrains notes the bounty came in at over $6,500, well below expectations given the severity, a pointed critique of OpenAI's security response.
More from Companies & People
- Anthropic sets up wet lab in Bay Area to pursue rare disease treatments — ivan_bezdomny · 2026-09-19
- Dev publicly trashes Microsoft AI Foundry onboarding: 18 screens and a credit card before giving up — altryne · 2026-09-19
- How Waterloo Became Silicon Valley's Favorite Talent Farm — kyliebytes · 2026-09-19
- Ascend VC's Kirby Winfield on his counterintuitive bet on defense-AI startup Overland AI — MartinGTobias · 2026-09-19
- YC Paper Club hosts Alternative Compute Paradigms event: optical CPUs, neuromorphics, bio GPUs — ycombinator · 2026-09-19
- MLSE in Toronto is hiring a data scientist for pro sports performance modeling — MeganRisdal · 2026-09-19