Researchers from Hacktron AI say they gained access to OpenAI’s internal repository by hijacking an employee account. According to their report, Anthropic’s Claude AI models helped them figure out the attack vector. The breach happened on July 25, and the whole process—from scouting for vulnerabilities to breaking in—took less than 72 hours.
How the Attack Went Down
The team chained together two exploits. The first let them run remote code by uploading an image to the community.openai.com forum, which runs on Discourse. The second flaw hit OpenAI’s single sign-on (SSO) and let them pivot from the compromised forum to get access to ChatGPT and Codex.
What Got Compromised
Hacktron AI says the key move was taking over an employee’s account, which opened the door to OpenAI’s internal repo. They didn’t share more details about what was inside that repo in their report.
Timeline and Tools
The timeline was tight: from the initial vulnerability hunt to reaching the internal repo, it took less than 72 hours. Claude models were used to help craft the attack strategy.
