How security researchers used Anthropic to hack OpenAI Security researchers at Hacktron used Anthropic's Claude Opus 5 to exploit a heap overflow vulnerability in the open-source image parser libheif and breach OpenAI's Discourse-based help forum, then chained a poorly configured SSO implementation to take over an OpenAI employee's account and gain access to OpenAI's GitHub repository, the firm announced Thursday. Hacktron said the full timeline from initial discovery to OpenAI repo access took less than 72 hours, and that until two months ago any user or OpenAI employee logging into community.openai.com could have had their ChatGPT and Codex accounts taken over. A team of security researchers was able to break into OpenAI's internal coding repository within hours of the release of Anthropic's Claude Opus 5 last July, leveraging a chain of vulnerabilities in an innocuous forum-hosting software application. The team at Hacktron discovered a heap overflow vulnerability in libheif https://github.com/strukturag/libheif?ref=thestack.technology , a popular open-source image parser used to process HEIF and AVIF images, and used that to infiltrate OpenAI's implementation of Discourse https://www.discourse.org/?ref=thestack.technology with help from Opus 5, they announced Thursday https://www.hacktron.ai/blog/hacking-openai?ref=thestack.technology . Once they had access to Discourse, they took advantage of a poorly configured SSO single sign-on implementation to take over an OpenAI employee's account, which granted it access to OpenAI's GitHub account. "Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum community.openai.com http://community.openai.com/?ref=thestack.technology could have had their ChatGPT and Codex accounts taken over," the researchers wrote. "The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours."