Hacktron researchers use Claude to help compromise OpenAI accounts
Hacktron chained a forum vulnerability with an OpenAI sign-in flaw, demonstrating internal repository access through a connected Codex account.
Compromise on July 25. Hacktron’s report metadata is dated September 13; its author posted the public thread September 18 UTC.
Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini report compromising OpenAI accounts on July 25, 2026. An image-processing vulnerability gave them control of the community forum; an OpenAI single-sign-on flaw extended access to ChatGPT and Codex. Hacktron AI
Using an employee’s connected Codex account, they created a harmless pull request in OpenAI’s internal repository. They say they avoided reading internal code and stopped testing. Access to other connected services was a potential consequence, not a demonstrated theft of their contents. Hacktron AI
AI assistance
S1r1us says Opus 4.8 found the image-library vulnerability and built a partial exploit; Opus 5 adapted it successfully to their Discourse test environment. Hacktron emphasizes that skilled human guidance remained important: this was researcher-directed work. Mohan Pedhapati (s1r1us) · X Hacktron AI
Disclosure and fixes
Hacktron reports an OpenAI fix approximately 14 hours after submission and a $6,500 bounty. Its write-up reproduces OpenAI’s clarification that the award covered the OpenAI-side finding; testing the Discourse-hosted forum was excluded from the bounty program. Hacktron AI
Discourse’s July 28 advisory confirms remote code execution through image uploads, identifies the upstream libheif vulnerability, and documents patched Docker images plus additional image-processing sandboxing. This vendor notice supports the forum vulnerability and remedy; it does not independently establish the OpenAI account-access chain. Discourse · GitHub Security Advisory
Sources & attribution
- Firsthand account 13 Sept 2026Hacking OpenAI
Hacktron AI. The page metadata dates the report September 13; the author’s X thread followed September 18 UTC (September 17 in US Central time).
- Firsthand account 18 Sept 2026S1r1us: OpenAI compromise and AI-assisted exploit development
Mohan Pedhapati (s1r1us) · X.
- Organizational disclosure 28 Jul 2026RCE via malformed HEIF file · GHSA-vhm9-85gw-x335
Discourse · GitHub Security Advisory.