Claude Helped Break Into OpenAI in Under 72 Hours — Via a Forum Image Parser and a Shared Login

On July 25, 2026, three researchers at the AI-assisted security firm Hacktron — Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini — chained two flaws to take over the ChatGPT and Codex accounts of several OpenAI employees and reach an internal code repository. From first look to internal access: under 72 hours. They proved it with a single harmless pull request in OpenAI’s internal monorepo, then stopped. OpenAI fixed the issue about 14 hours after the report and paid a $6,500 bounty on September 1. The team published the full writeup, “Hacking OpenAI,” on September 13.

The way in was an image file. OpenAI’s public help forum at community.openai.com runs on Discourse, which hands uploaded HEIC and HEIF images to ImageMagick, which reads them with the libheif library. A crafted image corrupted the forum server’s memory — and from there, a shared login did the rest. The forum offered “Sign in with OpenAI,” the same single sign-on staff use elsewhere, so controlling the forum server meant taking over the ChatGPT and Codex accounts of any OpenAI employee on it. The victims did nothing at all.

A patched library that never reached the server

The vulnerability at the bottom of the chain is tracked as CVE-2026-32882. Discourse’s advisory rates it remote code execution at 8.8. Upstream, the picture is narrower and more interesting: in libheif’s own record the flaw is an out-of-bounds read — a crash and a memory leak, not direct code execution. The leak matters because it defeats ASLR, the memory-layout randomization standing between a crash and a working exploit. The researchers, with AI help, did the remaining conversion work themselves.

Here is the part that should embarrass every image-processing pipeline owner: the upstream fix shipped in libheif 1.22.0 in May 2026, and the CVE was public — but the forum’s server image, built on Debian 12, still carried libheif 1.19.7 when the researchers looked in July. A web-interface update would not have replaced that library; only rebuilding on a current image would. Discourse-hosted sites were patched, and the fixed self-hosted releases are 2026.7.0, 2026.6.1, 2026.5.2, and 2026.1.6. If you run your own Discourse, this finding is a direct instruction: rebuild, don’t just update. If your service decodes HEIC, HEIF, or AVIF through libheif at all, check which build is actually running — the patched release as of early September is 1.23.4.

The model that stalled, and the model that didn’t

The exploit-development story is the sharpest capability datapoint in the writeup. The team first tried Claude Opus 4.8, which struggled across several sessions to build a working exploit once ASLR was enabled. Anthropic released Claude Opus 5 on the evening of July 24 — and in a fresh session it produced a working exploit within hours. Opus 5 shipped with safeguards against writing exploit code for real targets; the researchers routed around them by pointing the model at their own test server disguised as a capture-the-flag practice target, running it in an automated loop. They stress the work was not hands-off — skilled human direction still mattered — but the step-change between model generations, on the same task, days apart, is the kind of measurement defenders rarely get in public.

It also fits the year’s pattern: Anthropic has reported criminal and state-backed groups already using Claude models to run real intrusions, and independent evaluations had Opus 5 completing an enterprise cyber range in 8 of 10 attempts. The Hacktron result grounds those abstractions in a named target, a named CVE, and a 72-hour clock.

One login to rule the blast radius

Hacktron is explicit that the account takeovers were an OpenAI identity problem, not a forum-software problem: any first- or third-party service sharing that sign-on could have granted the same access. Because staff connect other services to ChatGPT and Codex, the team says the same foothold could in theory have extended to GitHub, Slack, and email. It was not used — the team opened one PR (#1186742, link redacted at OpenAI’s request), read no source, merged nothing, touched no customer data — but the blast-radius arithmetic is the lesson. A low-trust public service sharing SSO with internal tools converts a forum compromise into an everywhere compromise. OpenAI’s own framing is narrower: it said the award “recognizes the OpenAI-side finding, not the actions against Discourse,” noting the forum itself was outside its bounty scope.

Zoom out and the campaign looks bigger than one forum. Hacktron calls the wider project HEIF Heist: about two months hunting the same image-decoding flaw class across software used by other large companies, at under $3,000 in total AI spend — with a Next.js instance confirmed in Vercel’s own advisory, a Meta-adjacent libheif exploit confirmed by the maintainers, and only Shopify noticing the probing, when its image processors kept crashing under thousands of test uploads. The cost figure is the threat-intel headline: industrial vulnerability research at a hobbyist’s cloud bill.

What to do

  • Find every libheif in your estate and check the build, not the app version. Update to 1.23.4 or your distribution’s patched build, rebuild container and server images rather than relying on web-layer updates, and where you don’t need it, disable decoding of untrusted HEIF/HEIC/AVIF — or sandbox image processing in a locked-down worker. This bug class previously surfaced in Discourse’s AI surface; the parser layer is the steadier target.
  • Un-share your single sign-on. A public, low-trust service must never share an SSO domain with internal tools. Limit which services the identity provider trusts, and require fresh step-up authentication before sensitive actions instead of inheriting a session minted elsewhere.
  • Assume AI-assisted exploit development in your patch timelines. The Opus 4.8-to-Opus-5 gap — stalled for sessions, then working in hours — is a direct input to SLA math. A public CVE plus a diffable patch plus a frontier model is a complete exploit pipeline; “no public exploit yet” is no longer a rating factor you can lean on.
  • Watch for the probing pattern. Thousands of image uploads crashing media processors was the only signal Shopify saw. Alert on repeated decoder crashes and bursts of crafted-media uploads against forums, helpdesks, and any other upload endpoint.
  • Scope bounty programs to the trust boundary, not the server boundary. OpenAI’s “forum out of scope” framing is understandable, but the finding that paid was the SSO trust design. Define scope around where sessions and identities flow, because that is where attackers will chain.

The uncomfortable arithmetic: a public CVE, a two-month-unapplied library patch, and one shared login turned a help forum into staff account takeover and monorepo access — in under 72 hours, for $6,500, with the exploit co-written by a model released the night before. The forum was the door. The identity architecture was the building. And the model keeps getting faster at walking through both.

Sources: