cd /news/ai-safety/hackers-breach-openai-exposing-vulne… · home topics ai-safety article
[ARTICLE · art-134019] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Hackers breach OpenAI, exposing vulnerabilities in security systems

The Hacktron AI research team — Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini — disclosed on September 18 that it breached OpenAI's internal systems in July 2026, gaining access to employee ChatGPT and Codex accounts and private GitHub repositories using a specialized version of Anthropic's Claude Opus model. OpenAI confirmed the incident, said no sensitive user data or production systems were compromised, patched the reported vulnerabilities in approximately 14 hours, and awarded Hacktron a $6,500 bounty. The attack exploited a heap buffer overflow in the third-party libheif image library and an overly permissive single sign-on token, with the full attack chain executed within 72 hours.

by read2 min views1 publishedSep 18, 2026
Hackers breach OpenAI, exposing vulnerabilities in security systems
Image: Cryptobriefing (auto-discovered)

FoxTPNL / Wikimedia Commons (CC BY 4.0) A three-person security team used Anthropic's Claude to break into OpenAI's internal systems, earning a $6,500 bounty and raising uncomfortable questions about AI-powered hacking.

A group of security researchers managed to breach OpenAI’s internal systems in July 2026, gaining access to employee ChatGPT and Codex accounts as well as the company’s private GitHub repositories. The kicker: they used a rival AI company’s model to do it.

The Hacktron AI research team, composed of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, publicly disclosed the breach on September 18, roughly two months after exploiting the vulnerabilities. OpenAI confirmed the incident but said no sensitive user data or production systems were compromised.

How a rival’s AI helped crack OpenAI’s defenses #

The attack exploited two distinct weaknesses. The first was a heap buffer overflow in the libheif library, a third-party image processing tool integrated into OpenAI’s stack. The second was an overly permissive single sign-on (SSO) token that gave the researchers far more access than any external party should have had.

The Hacktron team used a specialized version of Anthropic’s Claude Opus model to develop their exploits. The researchers executed their full attack chain within 72 hours of starting work.

OpenAI responded quickly once notified, patching the reported vulnerabilities within approximately 14 hours. The company awarded Hacktron a $6,500 bounty for the responsible disclosure.

AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

The dual-use problem gets real #

The fact that the researchers used Claude, not a fine-tuned dark-web tool or a jailbroken model, matters. The researchers did not need to circumvent safety guardrails in any unusual way. They simply applied Claude’s coding capabilities to a security research workflow.

This incident is distinct from a prior episode in which OpenAI’s own AI agents reportedly compromised external systems, including infrastructure belonging to Hugging Face.

The libheif vulnerability is worth examining in context. Open-source libraries like libheif are embedded in thousands of software products across the tech industry. A buffer overflow in one of these dependencies is not a failure unique to OpenAI.

What this means for AI security and beyond #

The 14-hour response time is genuinely impressive by industry standards. Many organizations take days or weeks to remediate disclosed vulnerabilities.

The 72-hour timeframe is the number that should stick with anyone thinking about this space. Three days from start to internal GitHub access at one of the most prominent AI companies in the world.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hackers-breach-opena…] indexed:0 read:2min 2026-09-18 ·