
It is not every day that one AI giant‘s flagship model helps security professionals break into a rival company’s front door. During a legitimate bug bounty audit, a three-person research team at startup Hacktron AI used Anthropic’s Claude to chain two critical vulnerabilities together, reaching an OpenAI employee’s account and accessing internal software repositories.
The researchers—Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—were participating in OpenAI’s Bugcrowd program. After discovering the path and confirming their level of access, the team responsibly flagged the security gaps to OpenAI, earning a $6,500 bug bounty payout for their work, The Wall Street Journal reports.
Chaining forum image flaws to bypass single sign-on checks
The initial breach started at community.openai.com, OpenAI’s public discussion forum powered by Discourse. The researchers spotted a heap buffer overflow flaw in libheif, an open-source library used by ImageMagick to process uploaded HEIC and HEIF image files. When the team first tried developing an exploit using Claude Opus 4.8, the model struggled against memory protection barriers.
Everything changed when Anthropic released Claude Opus 5 on July 24. Switching to the newer model yielded a functional remote code execution payload within hours. From there, the team uncovered a single sign-on flaw where session tokens created on the public forum remained valid across internal tools like ChatGPT and Codex. The loophole gave them direct access to accounts belonging to OpenAI staff.
Proving repository access and forcing internal security changes
To prove they had reached internal networks without snooping on sensitive technical data or model weights, the researchers used a compromised employee’s Codex account to open pull request #1186742 inside OpenAI’s main software repository, named openai/openai.
OpenAI confirmed both vulnerabilities have been fixed, token permissions tightened, and affected sessions revoked. OpenAI president Greg Brockman revealed that the company redirected 25% of its production engineers to security tasks following this event and a prior testing escape incident. The entire audit took under 72 hours of work and cost less than $3,000 in total API token credits as part of Hacktron AI’s broader “HEIF Heist” research project.
The post Security Researchers Use Anthropic’s Claude Opus 5 to Hack OpenAI in Under 72 Hours appeared first on Android Headlines.