3 researchers hacked OpenAI in 72 hours for under $3,000 using Claude Opus
FinanceYF5 · x · 2026-09-21
Three Indian security researchers (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini) used Claude Opus to chain two critical vulnerabilities and take over OpenAI employees' ChatGPT/Codex accounts in under 72 hours.
- A heap buffer overflow in libheif, reached via ImageMagick and Discourse image uploads on community.openai.com
- An SSO identity misconfiguration that let any forum user log in as an OpenAI employee
- With account access, they could reach connected GitHub, Slack and email, and proved access by opening a PR in OpenAI's internal monorepo without reading sensitive data
They reported it immediately, coordinated patches with OpenAI and Discourse, and received a $6,500 bounty. None of the three had elite-school or big-tech backgrounds.
More from AGI Musings
- Indie Dev's Polished Game Jam Concept Cloned and Shipped, Probably via AI Prompt — erikphoel · 2026-09-21
- Amodei's coordinated AI slowdown plan flagged as a cartel; White House adviser calls it regulatory capture — mixtapedmonk · 2026-09-21
- Telegraph: No, AI Has Not 'Gone Rogue' — chu · 2026-09-21
- Every financial wave gets called a bubble: speculation funds the rails, says Lex Sokolin — LexSokolin · 2026-09-21
- 'We Must Regulate the Hurricane!' Satire Skewers AI Governance Debates — Pseudomanifold · 2026-09-21
- Andy Masley Launches Series Explaining Effective Altruism's 'Story of the World' Without Jargon — AndyMasley · 2026-09-21