Researchers from Hacktron AI used the Anthropic Claude language model to gain access to an OpenAI employee's ChatGPT account and, through that account, to internal code stored on OpenAI's GitHub, according to the American magazine Forbes. The team reported the vulnerability to OpenAI after discovering it.
How the intrusion was carried out
According to reports, the researchers first tried the Claude Opus 4.8 model without success; they were able to exploit the flaw using Opus 5. The Wall Street Journal says the group used a special variant of the model that is available to cybersecurity professionals.
Why this matters
The case highlights that more advanced AI models can substantially reduce the time and expert labor needed to discover vulnerabilities. The researchers stated that gaining access to OpenAI's systems would have taken the AI agent a few days, while the same work required only a few hours of human effort, indicating that models can automate and accelerate vulnerability discovery.
OpenAI's response and consequences
OpenAI thanked the researchers, patched the identified vulnerabilities, and paid $6,500 through its bug bounty program, according to statements provided to other outlets. OpenAI has emphasized that responsible disclosure and timely fixes are the intended outcomes of such programs.
Project context: HEIF Heist
The finding was part of a research effort called HEIF Heist, which investigates processing flaws in certain image file types. Hacktron AI said the two-month project involved three researchers, and that during the work they also identified vulnerabilities in systems belonging to Slack, Zoom and Meta.
Summary
The incident shows that advanced language models can uncover new and faster attack paths, but also underlines the importance of responsible disclosure and bug-fixing mechanisms. Detailed technical descriptions of the exploit and mitigation steps are available in the researchers' and press reports.



