OpenAI hacked by small team of white hat security researchers
Security researchers say they used Anthropic’s newly released Claude Opus 5 to help turn an image-processing vulnerability into an exploit chain that compromised an OpenAI employee’s ChatGPT account and reached the company’s internal GitHub environment — an incident that illustrates how AI coding agents are changing the economics of sophisticated vulnerability exploitation. The researchers, part of security startup Hacktron AI, disclosed the operation this week after reporting it to OpenAI and Discourse in July. The Wall Street Journal independently reported that the team gained access to an OpenAI employee’s ChatGPT account and had a path to read and propose changes to private OpenAI software. Hacktron says the researchers stopped short of examining sensitive source code. Instead, they used the compromised employee account’s access to Codex to create a harmless pull request in OpenAI’s internal monorepo, demonstrating that the account compromise could extend beyond ChatGPT itself into connected developer infrastructure. The company promoted a video released tonight by YouTuber @LiveOverflow discussing their approach: Video 3 The incident matters for enterprises because it combines three increasingly important security boundaries: vulnerable third-party infrastructure, federated identity and AI agents connected to business systems.
Hacktron has framed the OpenAI incident as part of a much broader libheif research campaign, saying the same line of work extended to Slack, Meta, Zoom, Shopify, GitHub Enterprise and other widely used platforms. In the accompanying video, the researchers go further, alleging that the team also “hacked Slack, Meta, and many more.” But its blog post and the supporting communications provided so far are focused overwhelmingly on OpenAI: they devote the detailed timeline, exploit chain, account-takeover mechanism, internal GitHub proof of access, disclosure process and bounty discussion to the OpenAI case, while the other companies are mentioned mainly as part of the wider HEIF Heist campaign rather than documented with the same level of technical detail or vendor confirmation. From an image upload to an OpenAI account The initial entry point was OpenAI’s community forum, community.openai.com, which runs on Discourse.