Researchers used Anthropic’s Claude to hack into OpenAI
Researchers used Claude Opus 5 to chain libheif and Discourse flaws, hijacking OpenAI employee ChatGPT and Codex accounts via bug bounty.
A three-person team at startup Hacktron AI chained a libheif memory bug (reached via crafted HEIF/HEIC uploads through Discourse's ImageMagick pipeline, never assigned a CVE) with an account-takeover flaw to access OpenAI employee ChatGPT and Codex accounts, one linked to OpenAI's GitHub organization. OpenAI paid a $6,500 bug bounty and says the issues are resolved; Discourse shipped a fix on July 27 after disclosure. Claude Opus 4.8 failed to produce a working exploit across several sessions, but Opus 5 succeeded within hours of release, underscoring how AI is collapsing the expertise needed to develop exploits.