Close Menu
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    TechtroduceTechtroduce
    Subscribe
    • NEWS
    • GUIDES
    • COMPARISONS
    • REVIEWS
    TechtroduceTechtroduce
    Home » Researchers Used Claude to Breach OpenAI Employee Accounts
    NEWS Updated:September 19, 2026

    Researchers Used Claude to Breach OpenAI Employee Accounts

    Abyan KhanBy Abyan KhanSeptember 19, 2026Updated:September 19, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Official Anthropic newsroom image representing the company and Claude branding
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers at Hacktron AI used Anthropic’s Claude to help develop an exploit chain that compromised OpenAI employee ChatGPT and Codex accounts and ultimately demonstrated access to an internal OpenAI GitHub repository. The research took place in July and was publicly disclosed this week after the vulnerabilities had been reported and fixed. OpenAI later paid Hacktron a $6,500 bug bounty for the OpenAI-side security issue.

    The attack began with OpenAI’s community forum, which runs on the Discourse platform. Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini found that specially crafted HEIC and HEIF images could reach a vulnerable version of the libheif image-decoding library through Discourse’s image-processing pipeline. By exploiting the memory-corruption flaw, the researchers achieved remote code execution on a test Discourse environment and then demonstrated the same capability against OpenAI’s community forum.

    Claude played a significant role in turning that vulnerability into a working exploit. Hacktron said Claude Opus 4.8 struggled across multiple attempts to produce reliable exploit code, but the situation changed after Anthropic released Claude Opus 5 on July 24. According to the researchers, Opus 5 produced a functioning ARM64 exploit for a local Mac within roughly three hours before helping adapt it to the x86-64 and jemalloc configuration used by Discourse.

    Official Anthropic newsroom image representing the company and Claude branding

    Remote code execution on the forum was only the first part of the chain. Hacktron then identified a separate problem involving OpenAI’s sign-in system, where Community authentication tokens carried broader permissions than necessary. The researchers said this could allow accounts belonging to people who had signed into the forum to be taken over at the ChatGPT and Codex level, including accounts used by OpenAI employees.

    That escalation substantially increased the potential impact because ChatGPT and Codex accounts can be connected to other workplace services. In the case Hacktron used for its demonstration, an OpenAI employee’s Codex account was connected to the company’s GitHub organization. Rather than examining proprietary source code, the team instructed Codex to create a harmless pull request in OpenAI’s internal monorepo, proving the level of access before ending further testing.

    OpenAI confirmed that it addressed the account-takeover issue. The company said it narrowed the permissions associated with Community sign-in tokens and revoked affected tokens and sessions after receiving the report. Discourse separately patched its image-processing vulnerability and added additional sandboxing around ImageMagick, while the underlying libheif issue has since been tracked as a high-severity vulnerability.

    The disclosure occurred through OpenAI’s Bugcrowd program, although the scope requires some distinction. Reporting indicates that testing against the Discourse-hosted community forum itself was outside OpenAI’s formal bounty scope, while the $6,500 award recognized the OpenAI-side sign-in vulnerability and resulting impact. Hacktron says the entire path from its initial discovery to demonstrating repository access took less than 72 hours.

    The researchers argue that the incident illustrates how advanced coding models can reduce the time and specialist knowledge required to turn memory-safety bugs into usable exploits. Hacktron’s broader research effort, called HEIF Heist, examined similar image-processing attack surfaces across several major technology platforms. Anthropic has also documented attempts to misuse Claude for cyber operations in its own threat intelligence reporting on malicious uses of Claude.

    The OpenAI incident is therefore notable for more than the initial forum compromise. A vulnerability in a third-party service, combined with overly permissive identity tokens and an employee account connected to developer infrastructure, created a path from an uploaded image to an internal software repository. The flaws have been patched, and the researchers say they deliberately avoided accessing sensitive internal code beyond what was necessary to demonstrate the security impact.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Abyan Khan
    • Instagram
    • LinkedIn

    Abyan Khan is a dedicated writer and tech enthusiast currently pursuing a Bachelor’s degree in Information Technology. With over 3 years of professional writing experience, he specializes in crafting clear, engaging, and informative content across a range of topics, particularly in the tech and gaming industries. Abyan combines his academic knowledge with real-world insights to deliver articles that are both well-researched and reader-friendly.

    Related Posts

    AMD RDNA 5 Rumor Claims Double Blackwell Matrix Performance

    September 19, 2026

    Riot Penalizes 296,416 LoL and VALORANT Accounts for Rank Manipulation

    September 19, 2026

    ARC Raiders Frozen Trail First Look Set for September 23

    September 19, 2026
    Leave A Reply Cancel Reply

    Google Techtroduce

    See more Techtroduce stories on Google.

    Add us on Google

    • AMD RDNA 5 Rumor Claims Double Blackwell Matrix PerformanceSeptember 19, 2026
      Kepler_L2 claims AMD’s RDNA 5 architecture could deliver roughly twice Blackwell and RDNA 4 matrix throughput per SIMD for FP4 and FP8 workloads.
    • Riot Penalizes 296,416 LoL and VALORANT Accounts for Rank ManipulationSeptember 19, 2026
      Riot says Vanguard has penalized 296,416 League of Legends and VALORANT accounts for boosting and other forms of ranked manipulation.
    • ARC Raiders Frozen Trail First Look Set for September 23September 19, 2026
      Embark will reveal ARC Raiders’ Frozen Trail update on September 23 ahead of its October 8 release, with a new map, ARC Operation and progression changes.
    TRENDING NOW

    Cyberpunk 2077 Reaches Highest Count Since February, Thanks To A Recent Announcement

    Avowed Will Feature More Than 10 Possible Endings

    Ubisoft Tells Players To Move On If They Cannot Handle Bugs In XDefiant

    Former Sony Devs Announce Cast Outs, a Magic-Fueled Co-Op Game For PS5

    Facebook Instagram YouTube
    © 2026 Techtroduce. All Rights Reserved | Cookies Policy | Privacy Policy | Contact Us | About Us | Corrections Policy

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}