Hacktron used Claude Opus 5 to breach OpenAI via Discourse and SSO flaws
The bug-bounty attack shows how quickly newer Claude models can turn a fresh software bug into an end-to-end exploit chain against live systems.
Security startup Hacktron AI used Anthropic’s Claude Opus 4.8 and 5 to help find and exploit a Discourse image-processing bug, then chained it with an OpenAI single sign-on flaw to take over OpenAI employee ChatGPT and Codex accounts. With those compromised employee identities, the team accessed OpenAI’s internal software systems, including private GitHub resources, and demonstrated their reach by submitting a pull request from an employee Codex account. Hacktron says Claude Opus 4.8 could not produce a working exploit for the underlying libheif vulnerability, but Opus 5 succeeded within hours of its release. The researchers ran the attack under OpenAI’s bug bounty program, reported the issues to both OpenAI and Discourse, and say they did not study or download OpenAI’s source code. OpenAI and Discourse have since patched the vulnerabilities, and OpenAI paid Hacktron a $6,500 bounty.
Why it matters
This incident illustrates how modern AI models can accelerate both sides of security work. Hacktron used Claude Opus 5 to turn an unpatched libheif bug into a working HEIF exploit, then chained it with an OpenAI SSO flaw to take over employee ChatGPT and Codex accounts and reach internal GitHub via a pull request. OpenAI and Discourse have since patched the flaws and paid a bounty, but Hacktron says the same exploit pipeline could be quickly adapted to other major platforms, underscoring how fast similar issues could be weaponized once discovered.