Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Security researchers turned to Claude to break through OpenAI’s defenses

Security researchers used Claude to hack OpenAI's systems, gaining access to its GitHub repo via a HEIF image flaw.

By mitch·4 min read
A hacker sits in front of glowing servers, coding on a computer screen in a dim room.

Three security researchers spent 72 hours hacking into OpenAI’s systems using Claude, the AI assistant built by Anthropic. The team, working under the name Hacktron, gained access to OpenAI’s GitHub repository, which holds what the Journal describes as the company’s “algorithmic secrets.” They announced the breach in a project called HEIST.

The attack worked through a corrupted image file and a weakness in the system that processes HEIF images. Hacktron says the exploit allowed remote code execution, or RCE, on Discourse Cloud, the third-party service that hosts OpenAI’s community forums.

How Hacktron Broke In

Hacktron’s method was simple in outline but precise in practice. The team used a corrupted image file to trigger a flaw in the system that processes HEIF images. That flaw gave them remote code execution on Discourse Cloud. From there, they accessed OpenAI’s instance.

Advertisement

The team did not actually access the code in Monorepo, the repository holding OpenAI’s algorithmic secrets. Instead, they sent a pull request from an employee’s Codex account to prove they had gained access. That proof was the demonstration of the breach.

According to Hacktron, Claude Opus 5 launched in the evening on July 24th. By 10AM the next day, the team had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.

The HEIST Project’s Reach

Hacktron says the HEIST project took “only one or two days” to adapt to different companies. The team targeted Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using less than $3,000 in tokens. They say the vulnerability was only detected by one target, Shopify.

The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed. OpenAI paid Hacktron $6,500 for finding the bug.

What Hacktron Says About the Threat

Hacktron CTO Mohan Pedhapati told the WSJ that the team is not as strong as Chinese threat actors. “We’re just three guys with Claude and Codex subscriptions,” he said.

That modesty carries a warning. Three researchers found a path into one of the world’s most valuable technology companies within 72 hours. If a team this small can move that fast, the question is not who else might find the same path, but how quickly they would act on it.

The Timeline of the Attack

Event Time
Claude Opus 5 launches Evening July 24th
RCE achieved on Discourse Cloud By 10AM July 25th
Access gained to OpenAI’s instance Within hours of RCE
Pull request sent from Codex account Confirmed proof of access
Vulnerability fixed Reported by Hacktron

The timeline shows a chain that moved from code release to full access in a matter of hours. The team’s speed is the story’s central fact.

What This Means for OpenAI

OpenAI now knows its systems are vulnerable in a way it did not know before. The company has fixed the reported flaws, and it paid Hacktron $6,500 for the information.

The breach also raises questions about the tools researchers use. Claude, the AI assistant behind the attack, is built by Anthropic. The fact that it helped break into OpenAI’s systems suggests the tools researchers rely on are becoming part of the attack surface itself.

The attack was not a brute-force effort. It was a targeted, deliberate use of a known vulnerability in a widely used forum system. That combination — a known flaw, a large attack surface, and a tool like Claude that can automate the search — is the pattern that keeps security teams awake at night.

The researchers’ own description of the project as a “heist” is telling. They treated the breach as a job, not an accident. They adapted their method to multiple targets in days, spending only $3,000 in tokens along the way.

Shopify was the only target that detected the vulnerability. The attack demonstrates that a single vulnerability can be present across multiple platforms, and that detection is not universal.

The payment of $6,500 means OpenAI treated the disclosure as a genuine contribution, not a threat.

Pedhapati’s remark that they are not as strong as Chinese threat actors, but “just three guys with Claude and Codex subscriptions,” puts the scale of the problem in perspective. If three researchers can do this, what can a nation-state do?

Here is the sequence of events, ranked by when they happened:

  1. Claude Opus 5 launches in the evening on July 24th.
  2. By 10AM the next day, the team achieves RCE on Discourse Cloud.
  3. Within hours of gaining RCE, the team accesses OpenAI’s instance.
  4. A pull request is sent from an employee’s Codex account, confirming proof of access.

Source material: “Security researchers used Claude to help them hack into OpenAI,” The Verge.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.