SDSignal Desk

Security researchers used Claude to help them hack into OpenAI

Sep 18, 2026, 8:30 AM · The Verge

Image: The Verge

Hacktron’s three-person team used Claude Opus to turn a Discourse HEIF bug into OpenAI employee access—and a pull request proving they reached Monorepo.

Why it matters

Stevie Bonifield’s Verge report, citing the Wall Street Journal, says Hacktron researchers took less than 72 hours to compromise OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5. They reached OpenAI’s GitHub “Monorepo,” described by WSJ sources as holding algorithmic secrets, stopped short of pulling internal code themselves, and sent a pull request from an employee’s Codex account to prove access.

Entry came through Discourse, which hosts OpenAI’s community forums, via a flaw in HEIF image processing. Hacktron says Claude Opus 5 launched the evening of July 24; by 10AM the next day they had RCE on Discourse Cloud and access to OpenAI’s instance. Their “HEIF Heist” adapted in one or two days to targets including Slack, Meta, GitHub Ent, Rails, Next.js, and ImageMagick, using under $3,000 in tokens; only Shopify detected them, to their knowledge.

Vulnerabilities reported to Discourse and OpenAI are fixed; OpenAI paid $6,500. Hacktron CTO Mohan Pedhapati told the WSJ they are “just three guys with Claude and Codex subscriptions,” not as strong as Chinese threat actors.

From the desk

We’re glad this landed as a bug bounty instead of a silent exfil—and we’re done pretending frontier models are only a safety-board abstraction.

A HEIF parser bug plus Claude as a force multiplier is classic dual-use: useful for defenders who move fast, catastrophic when the other side has more than three people and a bigger budget. Reaching Monorepo adjacency through a community forum is an organizational failure as much as a CVE.

Useful AI includes AI-assisted security research that closes holes before nation-states do. The $6,500 payout next to sub-$3,000 token spend is a market signal: labs are underpricing the offense these tools enable. Pedhapati’s line should haunt every CISO still treating chatbot subscriptions as harmless.

I’m watching whether Discourse-class vendors harden media pipelines industry-wide, whether OpenAI changes forum and SSO boundaries, and whether model providers publish misuse telemetry for HEIF-style exploit workflows.

Context

The Verge published on September 18, 2026. Hacktron framed the work as responsible disclosure after proving access without dumping Monorepo contents.

Who feels it

Frontier labs
Assume AI-accelerated bug finding against your SaaS perimeter is already commodity.
Forum and image-pipeline vendors
HEIF and media parsers need the same urgency as auth bugs.
Defenders
Budget AI-assisted red teams; waiting for $6,500 bounties is not a strategy.

What to watch

  1. Whether similar HEIF/Discourse class bugs appear in other major community stacks.
  2. Changes to OpenAI forum isolation and employee SSO after the PR proof.
  3. Industry movement on bounty amounts versus AI-accelerated exploit cost.

Read the original

Continue at the source.

The Verge

Companies: OpenAI, Anthropic

Also covering this