# Researchers Used Claude Opus 5 to Hack Into OpenAI’s Internal Systems

By Rafiqul Islam Rabbi · AI · Published Mon, 28 Sep 2026 08:36:05 GMT
Source: The Current Tribune — https://currenttribune.com/article/claude-opus-5-hacktron-openai-hack

A three-person security outfit just proved a point that ought to unsettle every company running a bug bounty program: for the price of a mid-tier phone plan, you can rent an AI model that breaks into a $500 billion company’s internal systems for you.

## How a Discourse Forum Became the Front Door

The team, Hacktron AI, didn’t go after OpenAI’s flagship products. They went after something far more mundane — the community forum OpenAI runs on Discourse software. That forum processes uploaded images, including the HEIF and HEIC formats that iPhones spit out by default, through two open-source libraries called ImageMagick and libheif. Buried in libheif was a memory-handling bug. Feed the server a specially crafted image, and instead of just displaying a photo, you can hijack the process handling it.

That first foothold, on its own, wasn’t the scary part. What Hacktron did next was.

### From One Bug to Employee Accounts

Once inside the Discourse server, the researchers found a second flaw that let them pivot from compromising the forum to taking over individual OpenAI employee accounts — including ones tied to the company’s GitHub organization. That’s the difference between defacing a forum post and reading a company’s source code.

## The Model That Made It Possible

Here’s the part that turns this from an ordinary vulnerability disclosure into an AI story: Hacktron didn’t write the exploit chain by hand. They had Claude do it. When they first tried this with Claude Opus 4.8, the model couldn’t produce a working exploit. Then Anthropic shipped Opus 5. Within hours of the upgrade going live, the newer model succeeded where its predecessor had failed.

That’s not a subtle capability jump. It’s a demonstration, in the wild, that a single model version bump moved a real target from “not exploitable by this tool” to “exploitable by this tool” in the space of a day.

### The Timeline

- **July 25:** Hacktron identifies and exploits the Discourse/libheif vulnerability

- **July 27:** Discourse ships a patch

- **September 18:** The full chain is disclosed publicly

OpenAI paid out $6,500 through its bug bounty program for the find — a rounding error against what the access could have been worth in the wrong hands.

## The Quote That’s Going to Get Repeated

Gray Swan CEO Matt Fredrikson summed up why this story is landing the way it is: “For $200 a month, anyone can use these tools and hack into a company like OpenAI.” That’s the price of a top-tier consumer AI subscription. It’s not a nation-state budget, and it’s not a specialized red-team contract. It’s a credit card.

Worth noting: this isn’t an isolated embarrassment for OpenAI specifically. OpenAI’s own AI agents have previously been used to breach Hugging Face during a separate cybersecurity evaluation, which means the pattern — capable models finding and chaining real vulnerabilities faster than defenders can patch them — is showing up on both sides of the OpenAI-Anthropic rivalry.

### Why This Is Different From a Normal Pentest

Security researchers have used automated tools to find bugs for decades. What’s new is the gap between “off-the-shelf chatbot” and “tool capable of chaining an image-parsing memory bug into a full account takeover” closing to nearly zero. A small team without a dedicated exploit-development budget got there in a single afternoon once they had access to a frontier model. That collapses the cost and skill floor for offensive security work in a way the industry hasn’t fully priced in yet — for better, if you’re the kind of researcher reporting it for a bounty, and for considerably worse if you’re not.

## What OpenAI’s Response Says

OpenAI’s fix moved fast at the infrastructure layer — the Discourse vulnerability was patched within two days of discovery. But speed at patching one bug doesn’t address the underlying dynamic: as models get better at synthesizing multi-step exploit chains, the number of similar bugs sitting undiscovered in any large company’s stack becomes the real exposure, not any single flaw.

## The Uncomfortable Math for Every Company’s Attack Surface

Large companies don’t run one piece of software. They run hundreds — internal wikis, support forums, ticketing systems, image processors, document converters, all bolted together over years by different teams who’ve long since moved on to other projects. Historically, finding a chainable bug across that sprawl required either an inside tip, a huge time investment, or a well-funded red team. Hacktron needed none of those things. They needed a subscription and a few days of prompting.

That’s the real shift buried in this story. It’s not that Claude found a bug — automated scanners find bugs constantly. It’s that a general-purpose model, not a specialized security tool built for this one job, reasoned its way through an entire multi-stage attack: identify the image-parsing flaw, weaponize it into server access, then pivot that access into an account takeover with real consequences. Each of those steps used to require a different kind of specialist. Now they’re steps in a single conversation.

## What This Means

This disclosure lands at an awkward moment for the entire industry’s safety narrative. Anthropic has spent much of the year talking about Claude’s growing role in legitimate research — the company recently touted the model directing roughly a quarter of its own internal R&D work. Hacktron’s demonstration is the other side of that same coin: the capability gains that make Claude more useful for defenders make it more useful for offense, too, and the tool doesn’t discriminate based on who’s typing the prompt. Expect this case to get cited in every future argument about mandatory capability evaluations before model releases, and expect OpenAI, Anthropic, and every other frontier lab to quietly widen their own bug bounty scope to cover exactly this kind of chained, AI-assisted attack before the next Hacktron shows up. The uncomfortable truth is that the defenders and the attackers are now shopping at the same store, and right now, the attackers only need to find one crack. The defenders have to find all of them.
