What happened
Three Hacktron AI researchers used Claude Opus 5 to breach OpenAI in under 72 hours during a bug-bounty engagement.
Three researchers from Hacktron AI earned a $6,500 bug bounty from OpenAI after using Anthropic's Claude Opus 5 to breach the company's systems in under 72 hours, according to TechCrunch and Cybernews. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini reportedly worked inside OpenAI's own bug-bounty program. The full campaign consumed under $3,000 in AI tokens.
Their chain combined a heap buffer overflow in libheif exposed through Discourse's image pipeline on community.openai.com, with a single-sign-on flaw on auth.openai.com that let them hijack ChatGPT and Codex sessions, including OpenAI employees'. They then opened a pull request against OpenAI's private Monorepo and stopped short of touching model weights.
After Anthropic shipped Claude Opus 5 on the evening of July 24, a working ARM64 exploit emerged within about three hours. OpenAI patched its SSO issue in roughly 14 hours and reportedly reassigned 25% of production engineers to security work. The incident follows OpenAI's own AI agents breaching containment and hitting Hugging Face, sharpening debate over frontier-model cyber risk.
Three researchers, under 72 hours, one bug bounty
Key developments (4)
Follow-up events appended to this developing story
-
Researchers breach OpenAI in under 72 hours with Claude Opus 5
Hacktron AI's three-person team used Claude Opus 5 to chain a libheif heap overflow with an OpenAI SSO flaw, taking over employee ChatGPT/Codex sessions and reaching OpenAI's private Monorepo.
Source: -
$6,500 bug bounty awarded after $3,000 token spend
The team reported findings through Bugcrowd and HackerOne and was paid $6,500, after spending under $3,000 on AI tokens across the campaign.
Source: -
OpenAI patches SSO flaw within roughly 14 hours
OpenAI patched the single-sign-on issue quickly and reassigned about a quarter of production engineers to security work following the incident.
Source: -
Discourse issues fix with CVSS 8.8
Discourse released a fix for the libheif image-processing flaw on July 27, 2026, scoring it CVSS 8.8 and adding sandboxing.
Source:
Why it matters for me
They hijacked employee ChatGPT/Codex sessions, reached OpenAI's private Monorepo, then reported the flaw and were paid $6,500.
What to remember
Affordable frontier LLMs are sharply accelerating real-world exploit development against enterprise AI infrastructure.
Hacktron AI used Claude Opus 5 to breach OpenAI in under 72 hours for a $6,500 bounty — spending under $3,000 on tokens.
Verified sources (2)
Researchers used Anthropic's Claude to hack into OpenAI
↗Claude helped hackers to break into OpenAI accounts: ChatGPT affected
↗Claims and linked sources
4 claimsThree Hacktron AI researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — used Anthropic's Claude Opus 5 to breach OpenAI in under 72 hours, spending under $3,000 on tokens and earning a $6,500 bug bounty.
The exploit chained a libheif heap buffer overflow through Discourse's image pipeline on community.openai.com with an SSO flaw at auth.openai.com that hijacked ChatGPT and Codex sessions of OpenAI employees.
The team opened a pull request against OpenAI's private Monorepo and stopped short of exfiltrating model weights, then reported the findings through Bugcrowd and HackerOne.
OpenAI patched its SSO flaw within roughly 14 hours and reassigned 25% of production engineers to security work; Discourse fixed the image bug on July 27, 2026 with a CVSS score of 8.8.