Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours
Hacktron researchers used Claude Opus 5 to exploit libheif and an SSO flaw, taking over OpenAI employee ChatGPT and Codex accounts within 72 hours.
Three Hacktron researchers chained a libheif image-parsing flaw in OpenAI's Discourse-hosted community forum with an SSO misconfiguration to hijack employee ChatGPT and Codex accounts, then opened a harmless pull request in OpenAI's internal monorepo as proof of impact. Claude Opus 4.8 could only build the exploit with ASLR disabled; Claude Opus 5 produced a working exploit within hours of its July 24 release. OpenAI patched roughly 14 hours after the report, and the broader HEIF Heist project covered Slack, Meta, and GitHub Enterprise for under $3,000 in AI spend. The researchers argue AI has made reliable exploit development drastically cheaper.