Three security researchers spent 72 hours hacking into OpenAI’s systems using Claude, the AI assistant built by Anthropic. The team, working under the name Hacktron, gained access to OpenAI’s GitHub repository, which holds what the Journal describes as the company’s “algorithmic secrets.” They announced the breach in a project called HEIST.
The attack worked through a corrupted image file and a weakness in the system that processes HEIF images. Hacktron says the exploit allowed remote code execution, or RCE, on Discourse Cloud, the third-party service that hosts OpenAI’s community forums.
How Hacktron Broke In
Hacktron’s method was simple in outline but precise in practice. The team used a corrupted image file to trigger a flaw in the system that processes HEIF images. That flaw gave them remote code execution on Discourse Cloud. From there, they accessed OpenAI’s instance.
The team did not actually access the code in Monorepo, the repository holding OpenAI’s algorithmic secrets. Instead, they sent a pull request from an employee’s Codex account to prove they had gained access. That proof was the demonstration of the breach.
According to Hacktron, Claude Opus 5 launched in the evening on July 24th. By 10AM the next day, the team had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.
The HEIST Project’s Reach
Hacktron says the HEIST project took “only one or two days” to adapt to different companies. The team targeted Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using less than $3,000 in tokens. They say the vulnerability was only detected by one target, Shopify.
The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed. OpenAI paid Hacktron $6,500 for finding the bug.
What Hacktron Says About the Threat
Hacktron CTO Mohan Pedhapati told the WSJ that the team is not as strong as Chinese threat actors. “We’re just three guys with Claude and Codex subscriptions,” he said.
That modesty carries a warning. Three researchers found a path into one of the world’s most valuable technology companies within 72 hours. If a team this small can move that fast, the question is not who else might find the same path, but how quickly they would act on it.
The Timeline of the Attack
| Event | Time |
|---|---|
| Claude Opus 5 launches | Evening July 24th |
| RCE achieved on Discourse Cloud | By 10AM July 25th |
| Access gained to OpenAI’s instance | Within hours of RCE |
| Pull request sent from Codex account | Confirmed proof of access |
| Vulnerability fixed | Reported by Hacktron |
The timeline shows a chain that moved from code release to full access in a matter of hours. The team’s speed is the story’s central fact.
What This Means for OpenAI
OpenAI now knows its systems are vulnerable in a way it did not know before. The company has fixed the reported flaws, and it paid Hacktron $6,500 for the information.
The breach also raises questions about the tools researchers use. Claude, the AI assistant behind the attack, is built by Anthropic. The fact that it helped break into OpenAI’s systems suggests the tools researchers rely on are becoming part of the attack surface itself.
The attack was not a brute-force effort. It was a targeted, deliberate use of a known vulnerability in a widely used forum system. That combination — a known flaw, a large attack surface, and a tool like Claude that can automate the search — is the pattern that keeps security teams awake at night.
The researchers’ own description of the project as a “heist” is telling. They treated the breach as a job, not an accident. They adapted their method to multiple targets in days, spending only $3,000 in tokens along the way.
Shopify was the only target that detected the vulnerability. The attack demonstrates that a single vulnerability can be present across multiple platforms, and that detection is not universal.
The payment of $6,500 means OpenAI treated the disclosure as a genuine contribution, not a threat.
Pedhapati’s remark that they are not as strong as Chinese threat actors, but “just three guys with Claude and Codex subscriptions,” puts the scale of the problem in perspective. If three researchers can do this, what can a nation-state do?
Here is the sequence of events, ranked by when they happened:
- Claude Opus 5 launches in the evening on July 24th.
- By 10AM the next day, the team achieves RCE on Discourse Cloud.
- Within hours of gaining RCE, the team accesses OpenAI’s instance.
- A pull request is sent from an employee’s Codex account, confirming proof of access.
Source material: “Security researchers used Claude to help them hack into OpenAI,” The Verge.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

