Three Hackers Breached OpenAI Internal Repos in 3 Days Using Claude for $3K
marcvanderchijs · x · 2026-09-21
Security team Hacktron AI disclosed that on July 25, 2026, they chained two critical vulnerabilities in under 72 hours — at roughly $3,000 in token costs — to compromise multiple OpenAI employees' ChatGPT accounts and reach internal OpenAI repositories.
Exploit chain:
- Heap buffer overflow in the libheif image decoder (missing Debian security backport; ImageMagick uses libheif; Discourse uses it for image uploads)
- SSO identity flaw in OpenAI's own forum, community.openai.com
- Access via ChatGPT / Codex accounts to connected integrations like GitHub, reaching internal repos
Proof: To demonstrate access without reading sensitive data, they used an employee's Codex to open PR #1186742 in OpenAI's internal monorepo.
The team reported to OpenAI and Discourse immediately and coordinated the patch; OpenAI paid a $6,500 bounty. The reposter notes that if three people can hack OpenAI in three days for $3,000, many banks are at risk too.
More from Safety
- Open models reach congressional staff: Washington is listening, for better or worse — ziv_ravid · 2026-09-21
- Amodei's coordinated AI slowdown plan flagged as a cartel; White House adviser calls it regulatory capture — mixtapedmonk · 2026-09-21
- Suricata 8.0.7 fixes dozens of CVEs as AI-assisted analysis drives vulnerability surge — jedisct1 · 2026-09-21
- jwt-simple has supported ML-DSA since v0.13, Post-Quantum OIDC table outdated — jedisct1 · 2026-09-21
- Insiders: OpenAI, Anthropic Oversold Security Breaches to Pressure Feds — -Psychologist- · 2026-09-21
- GoDaddy's ANS: Offline, Sub-Millisecond Agent Verification — someone_somewhere_9 · 2026-09-21