Three Hackers Breached OpenAI Internal Repos in 3 Days Using Claude for $3K

marcvanderchijs · x · 2026-09-21

Security team Hacktron AI disclosed that on July 25, 2026, they chained two critical vulnerabilities in under 72 hours — at roughly $3,000 in token costs — to compromise multiple OpenAI employees' ChatGPT accounts and reach internal OpenAI repositories.

Exploit chain:

Proof: To demonstrate access without reading sensitive data, they used an employee's Codex to open PR #1186742 in OpenAI's internal monorepo.

The team reported to OpenAI and Discourse immediately and coordinated the patch; OpenAI paid a $6,500 bounty. The reposter notes that if three people can hack OpenAI in three days for $3,000, many banks are at risk too.

Related event: Three Researchers Used Claude Opus to Breach OpenAI's Internal Repositories for About $3,000(5 posts)→

Original post →

More from Safety

Safety channel →