Researchers used Anthropic's Claude to hack into OpenAI employee accounts via Discourse HEIF flaw
A three-person Hacktron AI team used Claude Opus 5 to chain an un-CVE'd libheif bug in Discourse with an account-takeover flaw, reaching OpenAI employee ChatGPT and Codex accounts and the company's GitHub Monorepo; OpenAI paid a $6,500 bounty and both…
A three-person team at startup Hacktron AI used Anthropic's Claude Opus models to chain two Discourse flaws into a breach of OpenAI employee accounts. Crafted HEIF/HEIC image uploads triggered a libheif memory bug in Discourse's ImageMagick image pipeline; because that fix was never assigned a CVE, Discourse ran a vulnerable version. Combined with a second account-takeover flaw, this yielded remote code execution on Discourse Cloud, access to OpenAI's community forum instance, and takeover of employee ChatGPT and Codex accounts — one linked to OpenAI's GitHub organization, where the researchers reached the Monorepo and proved access with a pull request from an employee's Codex account. Per TechCrunch, Claude Opus 4.8 failed to produce a working exploit across several sessions while Opus 5 succeeded within hours of its release; The Verge, which dates the Opus 5 launch to July 24, puts access to OpenAI's forum instance within roughly a day of that launch. The team's 'HEIF Heist' tooling was adapted to targets including OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens, and only one target, Shopify, detected the activity. Discourse shipped a fix on July 27 after disclosure, and OpenAI says both issues are resolved and paid a $6,500 bug bounty.
- A three-person team at startup Hacktron AI used Claude Opus 4.8 and 5; per TechCrunch, Opus 4.8 failed to produce a working exploit across several sessions while Opus 5 succeeded
- Sources differ slightly on timing: Opus 5 succeeded within hours of release (TechCrunch); access to OpenAI's community forum instance came within roughly a day of Opus 5's July 24 launch (The Verge)
- Entry vector: crafted HEIF/HEIC image uploads triggering a libheif memory bug in Discourse's ImageMagick image pipeline; the libheif fix was never assigned a CVE, so Discourse ran a vulnerable version
- A second flaw enabled takeover of employee ChatGPT and Codex accounts, one linked to OpenAI's GitHub organization
- The researchers achieved RCE on Discourse Cloud, accessed OpenAI's community forum instance, reached the GitHub Monorepo, and proved access with a pull request from an employee's Codex account
- HEIF Heist tooling adapted to OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens; only Shopify detected the activity
- OpenAI paid a $6,500 bug bounty and says both issues are resolved
- Discourse shipped a fix on July 27 after disclosure
Coverage timelineoldest first · each row is one article
- · 3h agoResearchers used Anthropic’s Claude to hack into OpenAI
TechCrunch · Security· 70
Researchers used Claude Opus 5 to chain libheif and Discourse flaws, hijacking OpenAI employee ChatGPT and Codex accounts via bug bounty.
- · 1h agoSecurity researchers used Claude to help them hack into OpenAI
The Verge · AI· 66
Three Hacktron researchers used Claude Opus to breach OpenAI employee accounts through a Discourse HEIF flaw, reaching the Monorepo within 72 hours.