cd /news/ai-safety/security-researchers-used-claude-to-… · home topics ai-safety article
[ARTICLE · art-134310] src=theverge.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Security researchers used Claude to help them hack into OpenAI

A three-person team of independent security researchers at Hacktron used Anthropic's Claude Opus 4.8 and 5 to break into OpenAI employee accounts in less than 72 hours, gaining access to OpenAI's GitHub repository known as "Monorepo," The Wall Street Journal reported. The researchers exploited a HEIF image-processing flaw in Discourse, the third-party service hosting OpenAI's community forums, to achieve remote code execution on Discourse Cloud, and proved access by sending a pull request from an employee's Codex account. Hacktron said the HEIF Heist project cost less than $3,000 in tokens, was detected only by Shopify among its targets, and that OpenAI paid it $6,500 for the bug, which has since been fixed; Hacktron CTO Mohan Pedhapati told the WSJ, "I don't think we are as strong as Chinese threat actors… We're just three guys with Claude and Codex subscriptions.

by read1 min views1 publishedSep 18, 2026
Security researchers used Claude to help them hack into OpenAI
Image: The Verge

A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, The Wall Street Journal reports. They were able to access OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to The Wall Street Journal’s sources.

A three-person team of researchers used a corrupted image file and forum software to hack into OpenAI.

They stopped short of accessing internal code in Monorepo themselves, but sent a pull request from an employee’s Codex account to prove they gained access. They were able to get in through Discourse, the third-party service that hosts OpenAI’s community forums, by exploiting an issue with the system it uses to process HEIF images. According to Hacktron, Claude Opus 5 launched in the evening on July 24th, and by 10AM the next day they had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.

Their HEIF Heist project took “only one or two days” to adapt to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and others, using less than $3,000 in tokens, and to their knowledge, was only detected by one target, Shopify. The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron says OpenAI paid it $6,500 for finding the bug, but as Hacktron CTO Mohan Pedhapati said to the WSJ, “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

── more in #ai-safety 4 stories · sorted by recency
── more on @hacktron 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/security-researchers…] indexed:0 read:1min 2026-09-18 ·