Kya hua
Teen Hacktron AI researchers ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach kiya.
Hacktron AI ke teen researchers ne Anthropic ke Claude Opus 5 ka istemal karke OpenAI ki systems ko under 72 hours Mein breach kiya aur Bugcrowd/HackerOne ke through report karke $6,500 ka bug bounty jeeta. Harsh Jaiswal, Mohan Pedhapati aur Rahul Maini ke poora campaign sirf $3,000 se kam AI token kharcha par aaya.
Unka attack chain Discourse ki image pipeline (community.openai.com) par libheif ke heap buffer overflow se shuru hua, phir auth.openai.com ke SSO flaw se ChatGPT/Codex sessions hijack kiye gaye. Researchers ne OpenAI ke private Monorepo par pull request daal diya, lekin model weights chhune bina ruke.
Claude Opus 5 ka July 24 release hote hi roughly teen ghanton mein working ARM64 exploit taiyaar ho gaya. OpenAI ne SSO flaw ko lagbhag 14 ghanton mein patch kiya aur 25% production engineers ko security par reassign kiya. Yeh incident OpenAI ke apne agents ke Hugging Face breach ke kuch hi hafte baad aaya, jisse frontier-model cyber risk ki charchay aur tez ho gayi.
Three researchers, under 72 hours, one bug bounty
Key updates (4)
Is story ke aage ke updates β jaise protest, inquiry, verdict
-
Researchers breach OpenAI in under 72 hours with Claude Opus 5
Hacktron AI's three-person team used Claude Opus 5 to chain a libheif heap overflow with an OpenAI SSO flaw, taking over employee ChatGPT/Codex sessions and reaching OpenAI's private Monorepo.
Source: -
$6,500 bug bounty awarded after $3,000 token spend
The team reported findings through Bugcrowd and HackerOne and was paid $6,500, after spending under $3,000 on AI tokens across the campaign.
Source: -
OpenAI patches SSO flaw within roughly 14 hours
OpenAI patched the single-sign-on issue quickly and reassigned about a quarter of production engineers to security work following the incident.
Source: -
Discourse issues fix with CVSS 8.8
Discourse released a fix for the libheif image-processing flaw on July 27, 2026, scoring it CVSS 8.8 and adding sandboxing.
Source:
Kyun matter karta hai
Unhone employees ke ChatGPT/Codex sessions hijack kiye, Monorepo tak pahuncha, phir report karke $6,500 bounty jeeta.
Security
Demonstrated that frontier LLMs can materially accelerate vulnerability discovery and exploit development against enterprise AI infrastructure.
Incident Response
OpenAI patched its SSO flaw within roughly 14 hours and reportedly reassigned 25% of production engineers to security work after the incident.
Seedhi baat
Sasta frontier LLM ab enterprise AI infrastructure par exploit development ko kaafi tez kar raha hai.
Hacktron AI ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach karke $6,500 bounty jeeta β sirf $3,000 se kam token kharch.
Verified sources (2)
Researchers used Anthropic's Claude to hack into OpenAI
βClaude helped hackers to break into OpenAI accounts: ChatGPT affected
βClaims and linked sources
4 claimsHacktron AI ke teen researchers ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach kiya, $3,000 se kam token kharch kiya aur $6,500 bug bounty jeeta.
Attack chain Discourse ki image pipeline par libheif heap buffer overflow se shuru hua aur auth.openai.com ke SSO flaw se OpenAI employees ke ChatGPT/Codex sessions hijack kiye.
Team ne OpenAI ke private Monorepo par pull request daala aur model weights chhune bina ruka, phir findings Bugcrowd/HackerOne se report ki.
OpenAI ne SSO flaw ko lagbhag 14 ghanton mein patch kiya aur 25% production engineers ko security par reassign kiya; Discourse ne image bug ka July 27, 2026 ko fix (CVSS 8.8) daala.