VMTech
Discuss a project

Claude Opus 5 assisted Hacktron’s OpenAI bug-bounty breach

Claude Opus 5 assisted Hacktron’s OpenAI bug-bounty breach

Researchers chained two flaws in OpenAI’s environment

A three-person team at security startup Hacktron AI used Anthropic’s Claude to identify and exploit two critical vulnerabilities in an OpenAI bug-bounty exercise. The researchers accessed multiple OpenAI employees’ ChatGPT accounts and gained entry into company software. OpenAI awarded Hacktron $6,500 for the report and said it has resolved the issues.

The initial entry point was OpenAI’s community forum, which runs on Discourse. On July 25, the team submitted a specially crafted HEIF or HEIC image, formats commonly used by iPhones. During upload processing, Discourse converted the file to JPEG through ImageMagick and the libheif decoding library.

Hacktron said a memory flaw in libheif allowed the crafted image to trigger an incorrect calculation of the position of one image over another. That was sufficient to take control of the server. The libheif developers had fixed the underlying bug months before, but the fix had not been formally identified as a vulnerability and had not received a CVE identifier. Hacktron said that may explain why the Discourse deployment still used a vulnerable version.

Model capability changed the exploit outcome

Hacktron reported that a cybersecurity-oriented version of Claude Opus 4.8 could not initially build a functioning exploit despite several sessions. When Anthropic released Claude Opus 5, the researchers gave it the same task and said it succeeded within hours.

After gaining access to the Discourse server, the team found a second weakness that enabled account takeover for ChatGPT and Codex users, including OpenAI employees. Hacktron said it took over an employee account whose Codex instance was connected to OpenAI’s GitHub organization. The researchers then notified OpenAI and Discourse; Discourse issued a fix on July 27.

Dependency management becomes a central control

The incident arrives amid intensified scrutiny of advanced AI systems and their cyber capabilities. The broader industry context includes appearances by Anthropic and OpenAI at Anthropic and OpenAI at TechCrunch Disrupt 2026, where both companies are part of the continuing debate around AI development and safeguards.

Claude Opus 5 has not faced the security export restrictions applied to Mythos 5, which was temporarily locked down over concerns about advanced hacking capabilities. Hacktron founder Mohan Pedhapati said AI is reducing the scarce expertise needed to develop exploits, shortening work that once took months to days.

For businesses, the practical implication is to track the full chain of software components behind routine functions such as image uploads, and to assess upstream security fixes even when they are not accompanied by a CVE.

#cybersecurity#aisecurity#vulnerabilitymanagement#anthropic
Open analytics
On the site 0 views
min read 3 18.09.2026
Instagram

Claude Opus 5 assisted Hacktron’s OpenAI bug-bounty breach

Open the post on Instagram ↗