About this page

Tested and verified

We research, test, and verify every recommendation before it goes live.

Published by Tech Help Canada Staff

Written by a team with hands-on experience in marketing, SEO, and business technology.

Results across North America

Our work has driven 10M+ app downloads and 2,900% organic traffic growth for businesses we've worked with.

Editorially independent

Affiliate partnerships don't influence what we recommend. Our editorial team makes every call.

Some links are affiliate links. We may earn a commission at no extra cost to you.

Researchers say Claude helped breach OpenAI accounts in 72-hour bug-bounty hack

A three-person team at Hacktron AI says it used Anthropic’s Claude models to chain two vulnerabilities into access to multiple OpenAI employee ChatGPT accounts, with one compromised Codex connection giving the researchers a path to an internal OpenAI code repository.

The researchers said the July 25, 2026, incident took less than 72 hours from initial discovery to repository access. Hacktron said it reported the findings through OpenAI’s Bugcrowd program, that OpenAI fixed its side in roughly 14 hours, and that OpenAI later paid a $6,500 bounty.

The case is drawing attention because it shows how quickly capable AI systems can compress advanced vulnerability research. Hacktron’s account says Claude Opus 5 succeeded where Claude Opus 4.8 struggled, while OpenAI’s GPT-5.6 Sol later showed a further performance jump in the team’s wider HEIF Heist research against similar image-processing targets.

What Hacktron says happened

According to Hacktron’s write-up, the entry point was OpenAI’s community forum, which ran on Discourse and supported sign-in through OpenAI’s identity system. The researchers said they found a path through Discourse’s image-upload handling for HEIF and HEIC files, which are commonly used by iPhones.

The vulnerable chain involved an image-processing dependency called libheif. Discourse later published a GitHub security advisory for CVE-2026-32882, describing a high-severity remote-code-execution issue caused by malformed HEIF file uploads and advising affected self-hosted Discourse operators to rebuild with patched images.

Hacktron said the forum compromise alone was not the full issue. The more serious impact came from an OpenAI single sign-on flaw that let forum-level access escalate into ChatGPT and Codex account access. In one case, the researchers said an OpenAI employee’s Codex account was connected to OpenAI’s GitHub organization.

To demonstrate impact without reading internal code, Hacktron said it used the employee’s Codex access to open a harmless pull request in OpenAI’s internal monorepo, then stopped further testing.

Where Claude and GPT-5.6 Sol fit

The OpenAI breach described in Hacktron’s timeline was primarily Claude-assisted. The researchers said Claude Opus 4.8 helped inspect the Discourse Docker image and identify the vulnerable libheif package, but struggled to produce a reliable exploit under Discourse’s default configuration.

That changed after Anthropic released Claude Opus 5 on July 24, 2026. Hacktron said Opus 5 produced a working ARM64 exploit within three hours, then helped adapt it to the x86-64 environment used by Discourse.

GPT-5.6 Sol appears in Hacktron’s account as part of the broader HEIF Heist research, not as the main model behind the OpenAI proof of access. Hacktron said the team saw another capability jump from Opus 5 to GPT-5.6 Sol when exploiting similar vulnerabilities with little information about the target system beyond the fact that it was vulnerable.

That distinction matters. A headline that says researchers used Claude and GPT-5.6 Sol to hack OpenAI can blur two related but different claims: Claude was central to the reported OpenAI chain, while GPT-5.6 Sol was cited in the researchers’ wider work on the same class of image-processing problems.

OpenAI, Discourse and the bounty question

Hacktron said OpenAI confirmed a fix on July 25, roughly 14 hours after the initial report. The team also said OpenAI marked the issue resolved and paid the $6,500 bounty on September 1.

There is a scope wrinkle. In Hacktron’s published timeline, an OpenAI comment said testing against the Discourse-hosted community.openai.com property was excluded from OpenAI’s bug-bounty program. The comment said the bounty recognized the OpenAI-side finding, not the researchers’ actions against Discourse.

Discourse published its security advisory on July 28 and credited Hacktron AI Research as the reporter. The advisory said patched Discourse versions included the fixed libheif dependency and additional image-processing sandboxing as defense in depth.

TechCrunch reported that OpenAI said it had resolved the issues Hacktron uncovered. The Register reported that OpenAI and Anthropic did not respond to its requests for comment, while also citing Hacktron’s timeline and the Discourse advisory.

Why this matters beyond OpenAI

This was not described as a fully autonomous AI attack. Hacktron said skilled human guidance remained important. But the amount of work a small team could complete changed dramatically.

That matches a broader warning from the UK National Cyber Security Centre, which assessed in May 2025 that AI will almost certainly make elements of cyber intrusion operations more effective and efficient. The NCSC specifically pointed to AI-assisted vulnerability research and exploit development as a major area to watch, with the time between disclosure and exploitation likely to shrink further.

For Canadian businesses and site operators, the lesson is not that every AI model is about to autonomously break into production systems. The more immediate issue is that security through obscurity, slow patch cycles and loosely connected identity systems are getting weaker as defenses.

What site owners and developers should take from it

The OpenAI incident points to several practical security priorities without needing to study the exploit itself.

  • Patch image-processing pipelines quickly. Upload handlers often depend on deep stacks of libraries. A web-app update may not replace vulnerable system packages inside older containers.
  • Rebuild affected containers, not just web interfaces. Discourse’s advisory said the latest Docker image includes patched libheif, and Hacktron warned that a web-interface update alone may not replace the underlying image.
  • Keep SSO boundaries tight. A lower-trust community forum should not become a bridge into higher-value internal services.
  • Monitor repeated crashes and malformed uploads. Hacktron said many image processors crashed during the wider HEIF Heist research, but only Shopify detected the activity.
  • Assume exploitation windows are shrinking. Once a patch or near-patch exists, AI-assisted researchers and attackers can move faster than older security playbooks assume.

The uncomfortable part of this case is that OpenAI was not breached through an exotic AI-only failure. It was reportedly breached through a dependency flaw, a forum service and an identity configuration problem. AI made the work faster and cheaper, but the underlying risks were familiar.

The security bar is moving

OpenAI’s own GPT-5.6 release materials describe Sol as the company’s strongest cybersecurity model yet and say GPT-5.6 improves on exploit-related evaluations while remaining below OpenAI’s Critical capability threshold. Anthropic’s Opus 5 launch materials similarly describe stronger agentic coding ability while saying Opus 5 remains behind Mythos 5 on cybersecurity tasks.

Those details matter because the same tools that improve defensive code review, patch validation and security testing can also reduce the expertise needed to turn software flaws into working attack paths. Hacktron’s OpenAI disclosure is a bug-bounty case, not a criminal campaign, but it shows how quickly the cost curve is changing.

The near-term security response is less dramatic than the headlines: patch faster, isolate risky processing tasks, harden identity flows, review connected app permissions and treat AI-assisted vulnerability research as a normal part of the threat model.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email