Researchers at Hacktron AI managed to compromise OpenAI employee accounts and reach an internal repository of the company after chaining vulnerabilities with the help of Claude Opus 5, from Anthropic. The flaws were responsibly reported and yielded US$ 6,500 in bug bounty.
The group, formed by Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, claims to have completed the path from initial discovery to access to the internal environment in less than 72 hours. To demonstrate the level of access without consulting sensitive code, the researchers had Codex create a harmless pull request in OpenAI's internal monorepo.
The operation began on community.openai.com, the company's official forum based on Discourse. A vulnerability in the processing of HEIC and HEIF images allowed remote code execution.
A second flaw, related to the implementation of single sign-on (SSO) at OpenAI, allowed expanding access to ChatGPT and Codex accounts of users who had used the company's authentication, including employees.
Claude Opus 5 helped complete the exploit
The team had started the work with an earlier version of Claude, but encountered difficulties in making the exploit reliable. After the release of Claude Opus 5, the model produced in about three hours a working exploit for ARM64, later adapted to the environment used by the forum.
Hacktron emphasizes that the process still required guidance from experienced researchers and was not fully autonomous.
OpenAI received the report on July 25 and confirmed a fix on its side about 14 hours later. On September 1st, it closed the case and paid the US$ 6,500 to the team. The amount referred specifically to the vulnerability on OpenAI's side, while the Discourse flaw was handled separately.



