{"slug": "hackers-breach-openai-exposing-vulnerabilities-in-security-systems", "title": "Hackers breach OpenAI, exposing vulnerabilities in security systems", "summary": "The Hacktron AI research team — Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini — disclosed on September 18 that it breached OpenAI's internal systems in July 2026, gaining access to employee ChatGPT and Codex accounts and private GitHub repositories using a specialized version of Anthropic's Claude Opus model. OpenAI confirmed the incident, said no sensitive user data or production systems were compromised, patched the reported vulnerabilities in approximately 14 hours, and awarded Hacktron a $6,500 bounty. The attack exploited a heap buffer overflow in the third-party libheif image library and an overly permissive single sign-on token, with the full attack chain executed within 72 hours.", "body_md": "FoxTPNL / Wikimedia Commons (CC BY 4.0)\n\n# Hackers breach OpenAI, exposing vulnerabilities in security systems\n\nA three-person security team used Anthropic's Claude to break into OpenAI's internal systems, earning a $6,500 bounty and raising uncomfortable questions about AI-powered hacking.\n\nA group of security researchers managed to breach OpenAI’s internal systems in July 2026, gaining access to employee ChatGPT and Codex accounts as well as the company’s private GitHub repositories. The kicker: they used a rival AI company’s model to do it.\n\nThe Hacktron AI research team, composed of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, publicly disclosed the breach on September 18, roughly two months after exploiting the vulnerabilities. OpenAI confirmed the incident but said no sensitive user data or production systems were compromised.\n\n## How a rival’s AI helped crack OpenAI’s defenses\n\nThe attack exploited two distinct weaknesses. The first was a heap buffer overflow in the libheif library, a third-party image processing tool integrated into OpenAI’s stack. The second was an overly permissive single sign-on (SSO) token that gave the researchers far more access than any external party should have had.\n\nThe Hacktron team used a specialized version of Anthropic’s Claude Opus model to develop their exploits. The researchers executed their full attack chain within 72 hours of starting work.\n\nOpenAI responded quickly once notified, patching the reported vulnerabilities within approximately 14 hours. The company awarded Hacktron a $6,500 bounty for the responsible disclosure.\n\n### AI, tech, and the markets they move—in one daily briefing.\n\nDaily. Free. Join 34,000+ readers across crypto, finance, and policy.\n\n## The dual-use problem gets real\n\nThe fact that the researchers used Claude, not a fine-tuned dark-web tool or a jailbroken model, matters. The researchers did not need to circumvent safety guardrails in any unusual way. They simply applied Claude’s coding capabilities to a security research workflow.\n\nThis incident is distinct from a prior episode in which OpenAI’s own AI agents reportedly compromised external systems, including infrastructure belonging to Hugging Face.\n\nThe libheif vulnerability is worth examining in context. Open-source libraries like libheif are embedded in thousands of software products across the tech industry. A buffer overflow in one of these dependencies is not a failure unique to OpenAI.\n\n## What this means for AI security and beyond\n\nThe 14-hour response time is genuinely impressive by industry standards. Many organizations take days or weeks to remediate disclosed vulnerabilities.\n\nThe 72-hour timeframe is the number that should stick with anyone thinking about this space. Three days from start to internal GitHub access at one of the most prominent AI companies in the world.\n\n**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/hackers-breach-openai-exposing-vulnerabilities-in-security-systems", "canonical_source": "https://cryptobriefing.com/hackers-breach-openai-security-vulnerabilities/", "published_at": "2026-09-18 18:15:51+00:00", "updated_at": "2026-09-18 18:26:44.426878+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "large-language-models", "ai-products"], "entities": ["OpenAI", "Anthropic", "Claude Opus", "Hacktron AI", "Harsh Jaiswal", "Mohan Pedhapati", "Rahul Maini", "libheif"], "alternates": {"html": "https://wpnews.pro/news/hackers-breach-openai-exposing-vulnerabilities-in-security-systems", "markdown": "https://wpnews.pro/news/hackers-breach-openai-exposing-vulnerabilities-in-security-systems.md", "text": "https://wpnews.pro/news/hackers-breach-openai-exposing-vulnerabilities-in-security-systems.txt", "jsonld": "https://wpnews.pro/news/hackers-breach-openai-exposing-vulnerabilities-in-security-systems.jsonld"}}