Saturday, 19 September India Edition
The Pulse
← Back to feed
TechDeveloping56 minutes ago❖ LIVING STORY

Anthropic ke Claude se OpenAI hack karne wale researchers

Teen logon ki team ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach kiya, $3,000 se kam token kharch kiye aur $6,500 bug bounty jeeta.

01 / Kya hua

Kya hua

Teen Hacktron AI researchers ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach kiya.

Hacktron AI ke teen researchers ne Anthropic ke Claude Opus 5 ka istemal karke OpenAI ki systems ko under 72 hours Mein breach kiya aur Bugcrowd/HackerOne ke through report karke $6,500 ka bug bounty jeeta. Harsh Jaiswal, Mohan Pedhapati aur Rahul Maini ke poora campaign sirf $3,000 se kam AI token kharcha par aaya.

Unka attack chain Discourse ki image pipeline (community.openai.com) par libheif ke heap buffer overflow se shuru hua, phir auth.openai.com ke SSO flaw se ChatGPT/Codex sessions hijack kiye gaye. Researchers ne OpenAI ke private Monorepo par pull request daal diya, lekin model weights chhune bina ruke.

Claude Opus 5 ka July 24 release hote hi roughly teen ghanton mein working ARM64 exploit taiyaar ho gaya. OpenAI ne SSO flaw ko lagbhag 14 ghanton mein patch kiya aur 25% production engineers ko security par reassign kiya. Yeh incident OpenAI ke apne agents ke Hugging Face breach ke kuch hi hafte baad aaya, jisse frontier-model cyber risk ki charchay aur tez ho gayi.

Bug bounty paid to Hacktron AIAwarded after reporting findings through Bugcrowd and HackerOne.
$6,500
AI token spend for the campaignSpent on Claude/GPT tokens across the entire campaign.
Under $3,000
Time from discovery to demonstrated Monorepo accessFrom initial RCE on OpenAI's community forum to a pull request against OpenAI's private Monorepo.
Under 72 hours
Discourse advisory CVSS for the image bugDiscourse issued a fix on July 27, 2026 with sandboxing; OpenAI patched its SSO flaw in roughly 14 hours.
8.8
Background

Three researchers, under 72 hours, one bug bounty

Key updates (4)

Is story ke aage ke updates β€” jaise protest, inquiry, verdict

  1. Researchers breach OpenAI in under 72 hours with Claude Opus 5

    Hacktron AI's three-person team used Claude Opus 5 to chain a libheif heap overflow with an OpenAI SSO flaw, taking over employee ChatGPT/Codex sessions and reaching OpenAI's private Monorepo.

    Source:
  2. $6,500 bug bounty awarded after $3,000 token spend

    The team reported findings through Bugcrowd and HackerOne and was paid $6,500, after spending under $3,000 on AI tokens across the campaign.

    Source:
  3. OpenAI patches SSO flaw within roughly 14 hours

    OpenAI patched the single-sign-on issue quickly and reassigned about a quarter of production engineers to security work following the incident.

    Source:
  4. Discourse issues fix with CVSS 8.8

    Discourse released a fix for the libheif image-processing flaw on July 27, 2026, scoring it CVSS 8.8 and adding sandboxing.

    Source:
02 / Kyun matter karta hai

Kyun matter karta hai

Unhone employees ke ChatGPT/Codex sessions hijack kiye, Monorepo tak pahuncha, phir report karke $6,500 bounty jeeta.

Β· Β·

Β· Β·

03 / Seedhi baat

Seedhi baat

Seedhi baat
Sasta frontier LLM ab enterprise AI infrastructure par exploit development ko kaafi tez kar raha hai.

Hacktron AI ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach karke $6,500 bounty jeeta β€” sirf $3,000 se kam token kharch.

Screenshot ya share kar lo

Verified sources (2)

Evidence behind the crack
/TechCrunch

Researchers used Anthropic's Claude to hack into OpenAI

β†—
PrimaryPublished Sep 18, 2026
/Cybernews

Claude helped hackers to break into OpenAI accounts: ChatGPT affected

β†—
Corroborating

Claims and linked sources

4 claims
ClaimHigh confidence

Hacktron AI ke teen researchers ne Claude Opus 5 se OpenAI ko 72 ghanton mein breach kiya, $3,000 se kam token kharch kiya aur $6,500 bug bounty jeeta.

Linked evidence
ClaimHigh confidence

Attack chain Discourse ki image pipeline par libheif heap buffer overflow se shuru hua aur auth.openai.com ke SSO flaw se OpenAI employees ke ChatGPT/Codex sessions hijack kiye.

Linked evidence
ClaimHigh confidence

Team ne OpenAI ke private Monorepo par pull request daala aur model weights chhune bina ruka, phir findings Bugcrowd/HackerOne se report ki.

ClaimHigh confidence

OpenAI ne SSO flaw ko lagbhag 14 ghanton mein patch kiya aur 25% production engineers ko security par reassign kiya; Discourse ne image bug ka July 27, 2026 ko fix (CVSS 8.8) daala.

Linked evidence
Agli story3 min read

Meta ka Muse Mac pe aaya β€” ab AI aapke computer pe kaam kar sakti hai

Agli story padhein