cd /news/ai-safety/how-security-researchers-used-anthro… · home topics ai-safety article
[ARTICLE · art-134641] src=thestack.technology ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

How security researchers used Anthropic to hack OpenAI

Security researchers at Hacktron used Anthropic's Claude Opus 5 to exploit a heap overflow vulnerability in the open-source image parser libheif and breach OpenAI's Discourse-based help forum, then chained a poorly configured SSO implementation to take over an OpenAI employee's account and gain access to OpenAI's GitHub repository, the firm announced Thursday. Hacktron said the full timeline from initial discovery to OpenAI repo access took less than 72 hours, and that until two months ago any user or OpenAI employee logging into community.openai.com could have had their ChatGPT and Codex accounts taken over.

by read1 min views1 publishedSep 18, 2026
How security researchers used Anthropic to hack OpenAI
Image: Thestack (auto-discovered)

A team of security researchers was able to break into OpenAI's internal coding repository within hours of the release of Anthropic's Claude Opus 5 last July, leveraging a chain of vulnerabilities in an innocuous forum-hosting software application.

The team at Hacktron discovered a heap overflow vulnerability in libheif, a popular open-source image parser used to process HEIF and AVIF images, and used that to infiltrate OpenAI's implementation of Discourse with help from Opus 5, they announced Thursday. Once they had access to Discourse, they took advantage of a poorly configured SSO (single sign-on) implementation to take over an OpenAI employee's account, which granted it access to OpenAI's GitHub account.

"Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over," the researchers wrote. "The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours."

── more in #ai-safety 4 stories · sorted by recency
── more on @hacktron 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/how-security-researc…] indexed:0 read:1min 2026-09-18 ·