OpenAI hack by Claude, ZCode's git upload: week 38 in tech, ranked Three Hacktron researchers used a Claude-written exploit chain to breach OpenAI's internal GitHub repositories in under 72 hours, entering through a libheif heap buffer overflow in community.openai.com's HEIC image upload path, escalating via an SSO misconfiguration to employee ChatGPT/Codex accounts and Codex's GitHub integration. OpenAI fixed its part in about 14 hours and paid a $6,500 bounty; the underlying libheif bug had been patched upstream months earlier but never received a CVE, so no scanner flagged it. Gray Swan CEO Matt Fredrikson told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI. Week 38 of 2026 had the OpenAI hack, a Claude-written exploit that got three researchers into OpenAI's internal GitHub, a coding agent that uploaded users' git history, and a Microsoft memo calling AI training "the largest theft of labor in human history". Here are September 14 to 18, seven stories ranked by how much each changes your Monday as a developer, with what happened after each episode and the stamp it gets now. | | Story | Stamp now | |---|---|---| | 1 | Hacktron: a Claude-written exploit, a libheif bug with no CVE, OpenAI's internal repos, a $6,500 bounty | NEEDS REVIEW | | 2 | NYT v. OpenAI and Microsoft: the unsealed "theft of labor" memo | NEEDS REVIEW | | 3 | ZCode uploads your whole .git to Alibaba Cloud, encrypted to a key only Z.ai holds | REVERT | | 4 | Xiaomi streams a live RL training run, now about $2.4 million | SHIP IT | | 5 | Microsoft AI's Mustafa Suleyman calls Claude's constitution dangerous | NEEDS REVIEW | | 6 | Pion: Andon Labs lets an agent run a company; both real shops lose money | NEEDS REVIEW | | 7 | Claude Fable 5.1's cipher "solve", now disputed | NEEDS REVIEW was SHIP IT | Three researchers at Hacktron https://www.hacktron.ai/blog/hacking-openai got into OpenAI's internal GitHub repositories in "less than 72 hours" HN https://news.ycombinator.com/item?id=49749656 , 436 points . The chain, one link at a time: php HEIC image upload on community.openai.com Discourse - ImageMagick - libheif: heap buffer overflow - code execution + forum admin - SSO misconfiguration - takeover of employee ChatGPT/Codex accounts - Codex's GitHub integration - OpenAI internal repositories The exploit was written by Claude. Opus 4.8 failed across sessions, beaten by ASLR. Opus 5 produced a working ARM64 exploit within hours of its release. When the autonomous loop refused to attack a remote target, the team proxied it to look like a capture-the-flag, and it stopped refusing. The whole HEIF campaign, which also hit Slack and Meta, took two months, three people and under $3,000 in tokens. OpenAI fixed its part in about 14 hours and paid $6,500. What happened after. A blog post on Thursday became a Wall Street Journal exclusive https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba883 that evening, then TechCrunch https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/ and the Guardian https://www.theguardian.com/technology/2026/sep/18/openai-hacked-anthropic-claude-chatbot on Friday. Per TechCrunch, "OpenAI says it has resolved the issues"; the entry was July 25 and the Discourse fix July 27. Matt Fredrikson, CEO of Gray Swan, told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI." The detail that matters most: the libheif bug had been fixed upstream months earlier but never got a CVE , so no scanner told the forum to upgrade. The OpenAI hack needed no zero-day. A patch with no paperwork was enough. Why it is number one. You probably run an image library you never chose. Anything that accepts user uploads and calls ImageMagick may reach libheif. A first look on a Debian/Ubuntu box plain commands, run them yourself : dpkg -l | grep -i heif is libheif installed, which version? magick identify -list format | grep -i heic does ImageMagick decode HEIC here? IM6: identify If you don't need HEIC, ImageMagick's policy.xml can switch the coder off: