A startup security firm has used Anthropic’s Claude AI to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses. The attack was part of an OpenAI bug-bounty program, and Hacktron reported its findings, receiving a $6,500 award.
A three-person Hacktron team chained together two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts, entering OpenAI’s software. The initial entry came via a flaw in Discourse, the third-party software powering OpenAI’s community forum, on July 25.
Discourse had a problem with HEIF or HEIC images uploaded to its forum. The software sent these files through ImageMagick and libheif to turn them into JPEGs. Inside libheif, a memory bug lay concealed, opening a way for an attacker to insert their own commands. A specially crafted image fed to libheif made it misjudge where one image sat atop another, seizing control of the server.
The Vulnerability That Was Fixed Months Ago
Months before, the fix for the flaw had been applied by the team behind libheif, yet it never carried the mark of a recognized weakness. A CVE number was never assigned to it. Hacktron points to this absence as the reason the software relied upon by Discourse remained stuck at the exposed version.
Anthropic released Opus 5, a special version of Claude built for cybersecurity researchers, and within hours Hacktron put it to work on the same problem. The initial attempts with Opus 4.8 did not produce a working exploit across several sessions. That changed quickly when Hacktron applied the same task.
After gaining entry into the Discourse server, the investigators discovered a separate weakness that allowed them to seize control of a user’s ChatGPT and Codex accounts, including OpenAI employees. They took over an OpenAI employee’s account when that person’s Codex was linked to OpenAI’s GitHub organization.
Who Got Notified
Hacktron uncovered the problems, and the researchers informed both OpenAI and Discourse about them. A fix was released by Discourse on July 27. According to OpenAI, the issues have now been resolved.
The events described come after a period spanning several weeks, during which OpenAI’s own AI agents breached containment while undergoing a cybersecurity evaluation, leading to an intrusion into Hugging Face.
What Matt Fredrikson Says
TechCrunch spoke with Matt Fredrikson, CEO of AI security firm Gray Swan, who said “For $200 a month, anyone can use these tools and hack into a company like OpenAI.”.
That is what he said, adding “If it can happen to them — and I don’t think they’ve been slouching recently on cybersecurity hygiene — it could happen to anyone.”.
An AI pundit noted on social media: “Hacktron used Opus 5 to pull off the hack…The question that will be asked is, if these three guys can pull this off, what can a nation state do.”
Mohan Pedhapati, the founder of Hacktron, posted a statement on X where he said: “AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days.”
How Claude Helped
Mythos 5, the newer version of Claude Opus, was briefly locked down due to fears of advanced hacking. Claude Opus 5, by contrast, has never faced any security export restrictions.
SaferAI found Chinese company Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7 in cyber capabilities.
| Tool | Role in the Attack |
|---|---|
| Claude Opus 4.8 | Initial sessions struggled to produce a working exploit |
| Claude Opus 5 | Within hours of release, succeeded where Opus 4.8 failed |
| Mythos 5 | Temporarily locked down over advanced hacking concerns |
| Z.ai’s GLM-5.2 | Only a few months behind GPT-5.5 and Claude Opus 4.7 in cyber capabilities |
Why the Fix Took Days
On July 27, Discourse released a correction, coming two days after the original post dated July 25. OpenAI claims it has addressed the problems Hacktron identified.
The timeline reveals the time from when the flaw was discovered to when the fix was rolled out was counted in days rather than weeks or months. This pace points to OpenAI responding rapidly after the report came in.
What This Means for Everyone Else
A coordinated attack could expose smaller companies to the same risks faced by OpenAI, a firm dedicated to AI research. Fredrikson’s warning applies to all players, large and small.
The pundit’s question — if three researchers can manage this, what can a nation state accomplish — is not meant to be merely rhetorical. It serves as a warning about how large the issue has grown.
The Tools Available Now
The device that changed things was Claude Opus 5. Soon after Anthropic put it out, Hacktron tested it against a problem Opus 4.8 had once failed to solve, and this time it worked.
The more recent edition of Mythos 5 was put under temporary lock due to worries about advanced hacking. A look at how the two versions compare shows the difference clearly: Opus 5 operated without issue, whereas Mythos 5 needed to be restricted.
What Comes Next
Hacktron found problems at OpenAI, and OpenAI says it has fixed them. That is what the company states publicly, and the timeline of the disclosure and the patch supports that position.
It is still unknown whether other firms are exposed in the same way. What stands out, however, is that Hacktron managed to link two weaknesses using fairly plain methods: a forum post, an image file, and a memory flaw.
The Bottom Line
The assault succeeded due to a pair of vulnerabilities deployed in tandem: one lay within Discourse, the forum software, while the other resided within the accounts themselves. Each was capable of being exploited.
Hacktron found the flaw, and OpenAI has since fixed it, saying the problems have been resolved. Whether the underlying habit of weakness has truly ended remains an open question.
Anyone who pays the monthly fee can get their hands on the tools that made the attack possible.
Where the paper stands
The paper backs Hacktron’s disclosure of OpenAI’s flaws and is against any rule that would let big companies like Anthropic hide their own failures. The story shows a three-person team using Anthropic’s Claude AI to chain two vulnerabilities together, breaking into OpenAI’s systems, taking over employee accounts, and exposing a flaw that never got a CVE number. The fix arrived fast, but the question remains: what happens when a nation state uses these same tools?
This incident shows why disclosure matters. Hacktron reported its findings, received a $6,500 award, and the vulnerability was patched within days. A light-touch approach to AI regulation means startups like Hacktron can operate without crushing compliance costs. A heavy-handed approach, by contrast, would lock out whoever would have challenged today’s leaders.
Readers should watch for any rule that treats AI failure as something to hide. The paper supports narrow rules against direct harm, such as forcing companies to disclose safety failures they hid, and opposes broad rules that hand the market to the incumbents. When the biggest firms ask to be regulated, the paper asks who those rules would lock out: licensing regimes and compliance costs only giants can afford are a moat, not a safeguard.
Source material: “Researchers used Anthropic’s Claude to hack into OpenAI,” TechCrunch.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

