conv.

All stories
SecurityQuiet 31h · day 7

Claude Opus 5 used to breach OpenAI's internal systems in under 72 hours

Three researchers exploited a Discourse bug with Anthropic's AI to access OpenAI employee accounts and source code, earning a $6,500 bounty.

Part of a larger narrative

The AI Control Crisis

15 stories · since Sep 3 · newest 13m ago — AI systems are escaping human oversight at scale—breaching secure systems, generating harmful content, stealing intellectual property, and causing real-world…

  1. OpenAI agent breached Australian Medicare portal, PM says company took three months to disclose
  2. Bessent Says OpenAI Managers, Not AI Agents, Are to Blame for Hugging Face Hack
  3. Consumers sue OpenAI, Anthropic, Google, SpaceXAI for alleged AI development collusion
  4. Claude Opus 5 used to breach OpenAI's internal systems in under 72 hoursyou are here
  5. OpenAI forms independent advisory group on mathematics and AI
All 15 stories in this narrative →

What to know

  • Three Hacktron AI researchers exploited a Discourse image-processing vulnerability with Claude Opus 5 to breach OpenAI's internal systems, gaining access to employee accounts and the company's core algorithmic repository (Monorepo) in under 72 hours.
  • The breach demonstrates how advanced AI models have lowered the barrier to sophisticated cyberattacks—Opus 5 succeeded where Opus 4.8 failed, and the team obtained nearly unrestricted access with only basic AI subscriptions.
  • OpenAI awarded a $6,500 bug bounty for the breach despite the attackers gaining write access to critical source code, raising questions about whether the reward reflects the actual security risk.
  • The incident highlights vulnerabilities in both third-party services (Discourse) and OpenAI's own authentication practices (overly permissive tokens), issues the company says it has now resolved.

The dispute Whether the $6,500 bounty is proportionate to the actual security risk and impact of having achieved write access to OpenAI's core source repository. · positions read across 13 posts and comments

most voices

The bounty is absurdly low given the severity of write access to source code.

  • “opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol”

    @hailey.at · Bluesky ↗
many voices

This is a stark demonstration that AI has made sophisticated cyberattacks accessible to small teams without elite expertise.

  • “The attack shows how newer AI models can cut the time and expertise needed to exploit security flaws.”

    The Decoder · The Decoder ↗
some voices

Nation-states now have a realistic chance of stealing U.S. AI secrets given how easily this breach occurred.

  • “At a time when the US is engaged in a race with China for AI supremacy, the researchers who hacked OpenAI said the attack suggests that advanced cyber-savvy teams backed by nation-states have a very real chance of getting a peek at the…”

    Metacurity (paraphrasing Hacktron AI) · Metacurity ↗

Mohan Pedhapati Chief Technology Officer, Hacktron AIHacktron AI Security research firmOpenAI AI company attackedAnthropic AI company whose Claude was used in breach

Claude Opus 5 used to breach OpenAI's internal systems in under 72 hours
nypost.com

How it unfolded 3 developments, newest first · click a bar or a number to jump articlesvideosposts

Peak 12 pieces in two hours at Sep 18, 12 AM; 69 pieces over 7 days (36 articles · 1 video · 32 posts) Sep 16, 2 PM — 1 piece · 1 article — Google News 1Sep 16, 4 PM — quietSep 16, 6 PM — quietSep 16, 8 PM — quietSep 16, 10 PM — quietSep 17, 12 AM — quietSep 17, 2 AM — quietSep 17, 4 AM — quietSep 17, 6 AM — quietSep 17, 8 AM — quietSep 17, 10 AM — quietSep 17, 12 PM — quietSep 17, 2 PM — quietSep 17, 4 PM — quietSep 17, 6 PM — quietSep 17, 8 PM — quietSep 17, 10 PM — 1 piece · 1 article — Google News 1Sep 18, 12 AM — 12 pieces · 10 articles · 2 posts — Newswires 10, Bluesky 1, Mastodon 1Sep 18, 2 AM — quietSep 18, 4 AM — quietSep 18, 6 AM — 1 piece · 1 article — Newswires 1Sep 18, 8 AM — 1 piece · 1 post — Mastodon 1Sep 18, 10 AM — 6 pieces · 6 articles — Newswires 3, Google News 3Sep 18, 12 PM — 5 pieces · 2 articles · 3 posts — Mastodon 2, Newswires 2, Reddit 1Sep 18, 2 PM — 4 pieces · 2 articles · 2 posts — Google News 1, Newswires 1, Hacker News 1, +1 moreSep 18, 4 PM — 2 pieces · 2 posts — Mastodon 2Sep 18, 6 PM — 5 pieces · 5 articles — Google News 3, Newswires 2Sep 18, 8 PM — 3 pieces · 2 articles · 1 video — Newswires 2, YouTube 1Sep 18, 10 PM — quietSep 19, 12 AM — quietSep 19, 2 AM — 4 pieces · 1 article · 3 posts — Hacker News 1, Newswires 1, Bluesky 1, +1 moreSep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — 3 pieces · 2 articles · 1 post — Hacker News 1, Google News 1, Newswires 1Sep 19, 10 AM — 1 piece · 1 article — Newswires 1Sep 19, 12 PM — quietSep 19, 2 PM — 3 pieces · 1 article · 2 posts — Bluesky 1, Hacker News 1, Newswires 1Sep 19, 4 PM — 3 pieces · 3 posts — Mastodon 3Sep 19, 6 PM — 1 piece · 1 post — Bluesky 1Sep 19, 8 PM — quietSep 19, 10 PM — 1 piece · 1 article — Google News 1Sep 20, 12 AM — quietSep 20, 2 AM — 1 piece · 1 post — Bluesky 1Sep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — 1 piece · 1 post — Mastodon 1Sep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — 2 pieces · 2 posts — Bluesky 2Sep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — quietSep 21, 8 AM — quietSep 21, 10 AM — 1 piece · 1 post — Bluesky 1Sep 21, 12 PM — 3 pieces · 3 posts — Bluesky 2, Mastodon 1Sep 21, 2 PM — 2 pieces · 2 posts — Hacker News 1, Mastodon 1Sep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — 1 piece · 1 post — Bluesky 1Sep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — 1 piece · 1 post — Bluesky 1Sep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — quiet 123
Sep 17Sep 18Sep 19Sep 20Sep 21Sep 22now · 12:00 AM ET
  1. 3

    Security experts note AI has lowered the barrier to sophisticated exploits

    Coverage highlights how Claude Opus 5 succeeded where Opus 4.8 failed, demonstrating that newer AI models dramatically cut the time and expertise needed to discover and exploit security flaws. Researchers achieved full breach in under 72 hours.

    “Three security researchers used Anthropic's Claude models to break into OpenAI's internal systems through its community forum in less than 72 hours.”
    — The Decoder, Tech news outlet · source
    1. first by Channel News Asia, 5d ago · also Ars Technica, Ars OpenForum, The Verge, ZeroHedge, The Decoder, The New Stack +4

      9 more headlines
    • mrsdeborahlynn.bsky.social

      techcrunch.com/2026/09/18/r... Independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses.

      mrsdeborahlynn.bsky.socialBluesky1d ago8▲view on Bluesky ↗
    2 more of the top 3 · 10 posts in this stretch
    • patrickcmiller@infosec.exchange

      Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earn $6,500 Bug Bounty https:// hackread.com/cybersecurity-sta rtup-claude-ai-hack-openai-bug-bounty/

      patrickcmiller@infosec.exchangeMastodon4d agoview on Mastodon ↗
    • kernelia.bsky.social

      Investigadores usaron Claude de Anthropic para hackear OpenAI —

      kernelia.bsky.socialBluesky2d agoview on Bluesky ↗
    all of them →
  2. 2

    OpenAI confirms breach and patches both vulnerabilities

    OpenAI acknowledged two security issues—one in Discourse and another in OpenAI's own systems—and stated both are now resolved. The company narrowed permissions on community sign-in tokens and revoked affected sessions.

    “We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
    — OpenAI
    • Hackread@mstdn.social

      A three-person cybersecurity team used Anthropic’s Claude to help hack OpenAI during authorized research, taking over employee accounts and reaching an internal code repository in under 72 hours. The reward? A $6,500 bug bounty. Listen/Read: https:// hackread.com/cybersecurity-sta rtup-claude-ai-hack-openai-bug-bounty/ # Cybersecurity # OpenAI #…

      Hackread@mstdn.socialMastodon5d agoview on Mastodon ↗
  3. 1

    Wall Street Journal and news outlets disclose the breach

    Hacktron AI disclosed their findings for the first time to the Wall Street Journal. Coverage describes how the researchers breached OpenAI's internal systems using Claude, accessed the company's prized "Monorepo" source code repository, and received a $6,500 bounty from OpenAI's bug bounty program.

    “I don't think we are as strong as Chinese threat actors. We're just three guys with Claude and Codex subscriptions.”
    — Mohan Pedhapati
    1. first by Fortune, 5d ago

    2. first by The Coin Republic, 5d ago

    1 more claim →
    • @LukaszOlejnik@mastodon.social

      Team using Anthropic's Claude hacked into OpenAI's internal code repository. Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host. The stolen login tokens also worked on ChatGPT, including employees' accounts. Reward: a $6,500 bug bounty. …

      @LukaszOlejnik@mastodon.socialMastodon5d agoview on Mastodon ↗
    1 more of the top 2 · 2 posts in this stretch
    • opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol —

      @hailey.atBluesky5d agoview on Bluesky ↗
    all of them →
  4. background

    Researchers access OpenAI employee tokens and GitHub repository — Using the exploit, the team gained access to authentication tokens from OpenAI's Discourse forum, which were valid on ChatGPT and GitHub. They took over an employee account with Codex access connected to OpenAI's internal monorepo and demonstrated impact by initiating a pull request without accessing sensitive data.

  5. background

    Anthropic releases Claude Opus 5; exploit succeeds — Initial exploit attempts with Opus 4.8 failed. When Anthropic released Opus 5, Claude quickly found a way to successfully exploit the Discourse vulnerability in the image library, producing working attack code.

  6. background

    Hacktron AI researchers discover Discourse bug in OpenAI forum — Researchers identified a security flaw in how the Discourse community forum processed certain image files. They accessed a special version of Claude Opus 4.8 to begin developing exploit code.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by New York Post, 4d ago · also HN Frontpage, Inshorts, NY Post

    2 more headlines
  2. first by Gizmodo, 5d ago · also Metacurity

    1 more headline

and 7 smaller pieces

What people are saying 1 voices from 1 site · best of 13 · verbatim