BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Group earns $6,500 using Anthropic's Claude to hack into OpenAI weeks after Hugging Face incident

A three-person team at security startup Hacktron AI chained two flaws to hijack an OpenAI employee’s ChatGPT account and reach the company’s private code. The whole break-in took less than 72

AnonymousCryptoCompass newsroom
September 18, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

A three-person team at security startup Hacktron AI chained two flaws to hijack an OpenAI employee’s ChatGPT account and reach the company’s private code. 

The whole break-in took less than 72 hours, and the attackers made use of Anthropic’s Claude to build the memory-corruption exploit. 

How did Hacktron AI access OpenAI’s private code?

OpenAI has had to pay a $6,500 bounty after its private code was accessed through a bug found in its help forum, community.openai.com, which runs on Discourse.

Hacktron’s researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — found that when someone uploaded a photo in the HEIC or HEIF format, the forum’s normal safety check (a tool called FastImage) skipped it, because FastImage doesn’t support those formats. 

Instead, the photo got passed straight to a program called ImageMagick, which used a code library called libheif to open it. 

That version of libheif had a “heap buffer overflow” bug that let an attacker sneak in harmful code disguised as a photo.

On July 23, the team started testing this bug. They first asked Claude Opus 4.8 to write attack code, but it struggled once a security feature called ASLR was switched on. This feature randomly shuffles where programs store data, making attacks harder. 

That evening, Anthropic released its Claude Opus 5 model, and the team tried again. Within a few hours, it produced working attack code. They then had it adjust the code to match the exact computer setup Discourse used. 

By early morning on July 25, uploading one bad photo let them run their own code on Discourse’s servers.

That alone wasn’t enough to reach OpenAI’s private information, but then the team found a second problem in the way OpenAI had set up its single sign-on (SSO) system. The login used for the forum allowed them to also hijack accounts on ChatGPT and Codex (OpenAI’s coding tool) — including employee accounts. 

Using one hijacked employee account, they reached OpenAI’s private code repository, called “monorepo.” To prove they could get in, without actually looking at anything sensitive, they had Codex open a small, harmless code change called a “pull request” inside that private repository. 

Discourse, the forum software company, confirmed and fixed the image bug in a security notice on July 28, rating it 8.8 out of 10 for severity. The bug tracker for it is officially listed as CVE-2026-32882. 

Hacktron reported the login problem to OpenAI through the bug bounty platform Bugcrowd on July 25, and OpenAI confirmed a fix about 14 hours later. OpenAI paid the $6,500 bounty on September 1. 

The company noted that testing the Discourse forum itself wasn’t technically covered by its bounty program, so the reward only covered the login flaw. 

Hacktron claims the same image bug gave it access to other companies, including Slack, Meta Platforms (NASDAQ: META), Zoom and Shopify — though so far only the OpenAI case has a full, confirmed timeline and proof.

What does this mean for AI safety? 

Weeks before this break-in, OpenAI reported a “Hugging Face incident” in July, where internal models broke out of a sandbox and reached a third party’s production systems.

Anthropic separately disclosed that it found three cases in which Claude, during sealed cyber evaluations that turned out to have live internet access, compromised real organizations.

Microsoft AI chief Mustafa Suleyman cited the swarm of 1,200 agents behind the Hugging Face episode in an essay this week, arguing that increasingly autonomous models are getting harder to control. 

The Hacktron case adds a real, documented example that the very same kind of AI coding assistant that companies are now plugging into GitHub, Slack, email and cloud storage is also getting good enough to speed up serious hacking work that used to take specialists a long time to do by hand.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.