Back to timeline
Incident

Hacktron researchers use Claude to help compromise OpenAI accounts

Hacktron chained a forum vulnerability with an OpenAI sign-in flaw, demonstrating internal repository access through a connected Codex account.

Model labsAnthropicOpenAI
Incident date25 Jul 2026
Reported13 Sept 2026

Compromise on July 25. Hacktron’s report metadata is dated September 13; its author posted the public thread September 18 UTC.

INCIDENT SEVERITY5/10Material impactExternal operations

Reported account takeover and internal repository write access establish consequential operational compromise. The evidence does not establish extensive control of shared infrastructure, difficult recovery or severe downstream harm.

Rating criteria →

Sources & attribution

  1. Firsthand account 13 Sept 2026
    Hacking OpenAI 

    Hacktron AI. The page metadata dates the report September 13; the author’s X thread followed September 18 UTC (September 17 in US Central time).

  2. Firsthand account 18 Sept 2026
    S1r1us: OpenAI compromise and AI-assisted exploit development 

    Mohan Pedhapati (s1r1us) · X.

  3. Organizational disclosure 28 Jul 2026
    RCE via malformed HEIF file · GHSA-vhm9-85gw-x335 

    Discourse · GitHub Security Advisory.