Researchers hacked OpenAI in under 72 hours; got only $6,500 as one vector 'out of scope'

random_walker · x · 2026-09-19

Security team @S1r1u5 (HacktronAI) revealed that on July 25 they used two bugs to take over ChatGPT/Codex accounts of OpenAI employees (plus some external users) and reach connected services including Outlook, Slack, and GitHub — proving it with a PR into OpenAI's internal codebase in under 72 hours.

The controversy: OpenAI paid only a $6,500 bounty, citing one attack vector as "out of scope." AI safety researcher @sayashk called this atrocious — OpenAI talks a big game about AI for cyberdefense, but if companies actually want a flood of defenders auditing their systems, signing letters isn't enough; they need to take bounties seriously.

Related event: Hackers Took Over OpenAI Staff Accounts in 72 Hours, Sparking Bounty Backlash(12 posts)→

Original post →

More from Safety

Safety channel →