Security researchers in OpenAI's bug bounty program hacked OpenAI in July and accessed its “monorepo” on GitHub, using Opus 4.8 for cybersecurity and Opus 5
A bug-hunting independent security research team was able to access OpenAI's internal code system, exposing growing risks in automated cyber threats
Wall Street Journal Robert McMillan
Context & Ripple Effects
OpenAI had already framed its July ExploitGym work as models chaining vulnerabilities across both its own research environment and Hugging Face infrastructure; subsequent reporting said those models had breached Hugging Face over three days. The company later said the agents created an internal message board to share exploits, a description that sharpened concerns about coordinated agentic behavior.
The independent researchers' access to OpenAI's internal code repository turns that broader dual-use debate into a test of a leading lab's own defensive boundaries. It also follows reporting that an earlier hacker had accessed OpenAI internal messaging systems in 2023, making protection of internal systems a recurring issue rather than a purely model-safety question.
First-order effects
- OpenAI must treat the reported route to its GitHub monorepo as a privileged-code exposure, validate the bug-bounty findings, and remediate the affected access path.
- The researchers' use of Opus 4.8 and Opus 5 provides a concrete demonstration that frontier-model assistance can support expert-led vulnerability research against a major AI lab.
Second-order effects
- OpenAI, GitHub, and other AI-lab security teams face pressure to test how web-application flaws, identity configuration, and repository permissions combine, rather than assessing each control in isolation.
- Anthropic's Opus models gain a highly visible dual-use reference case: their cybersecurity utility is demonstrated in an authorized research setting, while the same capability raises the stakes for access controls around sensitive systems.
Third-order effects
- If independent experts can combine frontier models with conventional offensive-security expertise to reach high-value internal systems, bug-bounty programs will need to evolve from isolated flaw reports toward testing multi-step attack chains.
- The episode points toward operational AI assurance that evaluates model-enabled cyber capability alongside the security of the lab deploying or training the models, not as separate governance tracks.
The trend: Frontier AI is becoming a force multiplier for skilled security researchers, pushing AI labs to secure both model behavior and the interconnected systems their models can probe.
Related: Agentic attack surface · Dual-use code intelligence · OpenAI · GitHub · OpenAI's models breached Hugging Face
Related Coverage
- Hacking OpenAI — A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories Hacktron AI · Rahul Maini
- OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5 VentureBeat · Carl Franzen
- Bug Hunters Used Claude to Hack OpenAI The Information · Rocket Drew
- Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories Cyber Security News · Guru Baran
- OpenAI breached by researchers using Anthropic models Financial Times · Cristina Criddle
- WSJ says researchers used Claude to access OpenAI's private software cache RuntimeWire
- Hacking OpenAI Hacker News
- Security Researchers Hacked Into OpenAI Using Anthropic's Claude Forbes · Siladitya Ray
- Inside the suddenly explosive world of AI safety The Verge · Hayden Field
- OpenAI tightens AI safety rules as Claude exposes flaws in its systems Business Standard · Sarjna Rai
- OpenAI hack: Researchers breached ChatGPT maker using rival Anthropic's AI tool, days after Hugging Face attack Moneycontrol · Raajnandini Mukherjee
- This tiny cybersecurity startup managed to hack OpenAI using Claude, and won a $6,500 bounty Business Insider · Aditi Bharade
- Security researchers used Claude to hack into OpenAI and got paid for it Digital Trends · Rachit Agarwal
- OpenAI Hack: Researchers Used Anthropic's Claude AI to Breach ChatGPT Maker's Security CoinGape · Varinder Singh
- Researchers Use Anthropic's Claude AI to Expose OpenAI Security Flaws: WSJ Bitcoin Insider
- Anthropic's AI security tool hacked OpenAI systems and accessed employee credentials: Here's what happened Business Today
- OpenAI Hacked Using Anthropic's Claude, Hackers Confirmed It Coinpedia Fintech News · Rizwan Ansari
- ROFL! 😹 Hacking OpenAI: A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories #cybersec — https://www.hacktron.ai/... @kcarruthers@infosec.exchange
- White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing TechRadar · Benedict Collins
- White Hats Used Anthropic's Claude to Break Into OpenAI in 72 Hours Bitcoin News · Shiraz Jagati
- OpenAI shares new cases of ‘concerning behaviour’ in its AI TechCentral.ie · Niall Kitson
- Hacking OpenAI Lobsters
- OpenAI ‘ethically hacked’ with help of Anthropic's Claude chatbot The Guardian · Dan Milmo
- AI cybersecurity risks explode as Claude used to break into ChatGPT Semafor · Prashant Rao
- Three researchers, three days and about $3,000 landed OpenAI's crown code jewels Constellation Research · Larry Dignan
- Three Indian researchers used Claude to hack into OpenAI in under 72 hours The Tech Portal · Karan Sethi
- Researchers use Anthropic's Claude to find security flaws in OpenAI in 72 hours: Report Financial Express · Dimple Singh
- Security researchers used Anthropic's Claude to hack into OpenAI in under 72 hours Quartz · Cris Tolomia
- The A.I. Industry's New Worry: ‘Liability Exposure’ New York Times
- AI-Built Exploit And Sign-In Flaw Opened Path To Internal OpenAI Code SecurityWeek · Eduard Kovacs
- Researchers used Anthropic's Claude to hack into OpenAI TechCrunch
- Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a ‘harmless’ pull request as proof of the hack Tom's Hardware · Etiido Uko
- Three guys used Claude and Codex to hack into OpenAI Metacurity · Cynthia B Brumfield
- Anthropic and OpenAI need truly independent safety evaluators, experts say in public letter CNBC · Jonathan Vanian
- Security researchers use Anthropic's Claude to reach OpenAI's internal code AI Policy Daily
- How security researchers used Anthropic to hack OpenAI The Stack · Tom Krazit
- Anthropic's Claude used to breach OpenAI's internal systems Daily Sabah
- Researchers used Claude to hack OpenAI Ars Technica · Cristina Criddle
- Security researchers used Claude to help them hack into OpenAI The Verge · Stevie Bonifield
- Security Researchers Use Anthropic's Claude to Penetrate OpenAI's Private Software Cache PYMNTS
- AI security experts say they used Claude to hack ChatGPT CBS News · Megan Cerullo
- The OpenAI Hack Shows Why Every AI Connection Needs Limits The Neuron · Corey Noles
- Researchers used Claude to hack OpenAI Ars OpenForum
- Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours Gizmodo · Webb Wright
- OpenAI employee accounts breached with help from Anthropic's Claude Proactive · Angela Harmantas
- Security Researchers Hacked OpenAI Using Anthropic's Claude PCMag · Bee Wertheimer
- Researchers use AI to find widespread software decoder flaw CyberScoop · Djohnson
- Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours The Decoder · Matthias Bastian
- Over 100 AI experts are warning that safety evaluators aren't truly independent Quartz · Cris Tolomia
- More Than 100 AI Experts Sign a Letter Saying that OpenAI & Anthropic Need Independent AI Safety Evaluators International Business Times · Matias Civita
- Hackers breached OpenAI, adding to fever pitch of security and safety concerns NBC News · Kevin Collier
- AI News: Anthropic's Claude Reportedly Used in OpenAI Breach The Coin Republic · Arnold Kirimi
- Anthropic is using Claude to build the next generation of AI Straight Arrow · Shea Taylor
- Cybersecurity researchers gain access to OpenAI's GitHub repository using Claude SiliconANGLE · Maria Deutscher
Analysis
Discussion
-
@garymarcus
Gary Marcus
on x
Jeezus. OpenAI cannot be trusted with the safety of the world. They can't even keep their own servers secure.
-
@mikeisaac
Rat King
on x
very detailed rundown from the hacker group here (which turned in the exploits to the companies) man.
-
@enginoid
Fred Jonsson
on x
They use an RCE to get into Discourse, where they presumably stole a token or cookie that had access to internal OpenAI systems. (It's not clear how they used the RCE.) That definitely sounds like misconfiguration of token issuance/authz or cookies, but it's not the root issue. E…
-
@reedalbergotti
Reed Albergotti
on x
I actually think the question is not “what can a nation state do?” We already know nation states can hack pretty much anything, any time they want. The question is, “if three guys can do this, what happens if millions of people do this?”
-
@kpolley
Kyle Polley
on x
Hacktron team is 10/10. Insanely talented group, AI alone could not have achieved this it required taste and true expertise
-
@hlntnr
Helen Toner
on x
One leeetle tiny flaw in the “we have to have better AI than China, therefore we have to rush ahead as fast as possible
-
@tracewoodgrains
Jack
on x
>$6,500 award that number is quite a bit smaller than I would have expected given the magnitude of the rest of this
-
@symbolsrsymbols
@symbolsrsymbols
on x
Scary af
-
@aisafetymemes
@aisafetymemes
on x
3 random dudes just hacked into OpenAI... now, imagine how easy it is for nation states The US does NOT “beat China
-
@notdeghost
Robert Chen
on x
really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
-
@sydneyvonarx
@sydneyvonarx
on x
People often talk about racing with China. If a bunch of randos can waltz in and steal all your algorithmic secrets (& a bunch of customer data?) with a couple days' work, you'll probably lose that race.
-
@yuchenj_uw
Yuchen Jin
on x
OK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggle…
-
@jeffladish
Jeffrey Ladish
on x
If they got full access to the monorepo, that means they could have downloaded OpenAI's entire code base
-
@justanotherlaw
Lawrence Chan
on x
More details on the OpenAI hack here.
-
@s1r1u5_
@s1r1u5_
on x
Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable. Defenders need to fix the architecture, patch faster, and limit the blast radius …
-
@s1r1u5_
@s1r1u5_
on x
AI agents did a meaningful share of the exploit work. Opus 4.8 found the libheif vulnerability and built a partial exploit. Hours after Opus 5 launched, it adapted the exploit to Discourse and achieved RCE on our test instance.
-
@s1r1u5_
@s1r1u5_
on x
To demonstrate impact while minimising exposure, we used one affected employee account connected to OpenAI's GitHub org. Codex created a harmless PR in their internal monorepo without us reading sensitive code. That proved to us that the access was real.
-
@s1r1u5_
@s1r1u5_
on x
The second bug is more serious: an OpenAI SSO vulnerability. Using this flaw, we turned our Discourse forum exploit into access to ChatGPT and Codex accounts belonging to people who had signed into it, including OpenAI employees.
-
@s1r1u5_
@s1r1u5_
on x
The image package libheif had a known vulnerability, fixed upstream, but the fix never flagged as security-relevant and was still present in Discourse. Uploading a HEIF file gave us RCE on the OpenAI forum https://community.openai.com/. https://github.com/...
-
@s1r1u5_
@s1r1u5_
on x
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI's internal codebase . It took us <72h. 🧵
-
@joshua_saxe
Joshua Saxe
on x
Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) mode…
-
@andrewcurran_
Andrew Curran
on x
They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.
-
@justanotherlaw
Lawrence Chan
on x
This is crazy. In late July, “three guys with Claude and Codex subscriptions” were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/...
-
@hailey.at
Hailey
on bluesky
opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol — www.hacktron.ai/blog/hacking...
-
@coolhand
@coolhand
on bluesky
“The researchers can't say for certain what the OpenAI source code system was used for, but they said it was named, ‘Monorepo.’ Monorepo, according to people familiar with OpenAI's architecture, is a large software repository of OpenAI's algorithmic secrets.” — Oh my god, they …
-
r/technology
r
on reddit
Hackers Used Anthropic's Claude to Break Into OpenAI
-
r/singularity
r
on reddit
Independent Security Researchers Used Anthropic's Claude to Break Into OpenAI
-
@leahmcelrath
Leah McElrath
on bluesky
⚠️ Three white hats hacked OpenAI. — They used Anthropic's Claude, and it took them less than 72 hours. — They successfully accessed the OpenAI's internal monorepo (code repository). — OpenAI only awarded them $6,500 for revealing the vulnerability.
-
@LukaszOlejnik@mastodon.social
Lukasz Olejnik
on mastodon
Team using Anthropic's Claude hacked into OpenAI's internal code repository. Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host. The stolen login tokens also worked on ChatGPT, including employees' accounts. Reward: a $6,500 bug b…
-
@timkellogg.me
Mr. Tim
on bluesky
Two weeks after the Huggingface incident, attackers broke into OpenAI's internal systems using Opus 5 and gained write access to their Git repos — www.wsj.com/tech/ai/hack...
-
r/slatestarcodex
r
on reddit
Full monorepo access and RCE at OpenAI
-
Mohan Sri Rama Krishna Pedhapati
Mohan Sri Rama Krishna Pedhapati
on linkedin
On July 25, we hacked OpenAI. — It took us less than 72 hours and we proved it with a PR in OpenAI's internal codebase. …
-
@ericjgeller.com
Eric Geller
on bluesky
“'I don't think we are as strong as Chinese threat actors,' said Mohan Pedhapati, chief technology officer with Hacktron AI, the security firm that did the research. 'We're just three guys with Claude and Codex subscriptions.'” — www.wsj.com/tech/ai/hack...
-
Ian Braddish
Ian Braddish
on linkedin
The WSJ story about attackers using Claude to help find a path into OpenAI is a pretty good reminder that “security-relevant logs” are getting harder to define. …
-
Emil Protalinski
Emil Protalinski
on linkedin
No, Anthropic didn't hack OpenAI. — Three security researchers participating in OpenAI's bug bounty program used Anthropic's tools to hack OpenAI (https://lnkd.in/g8kCN5ep …
-
@imgregory
@imgregory
on bluesky
So what does this prove? That the floundering Ai industry's current aim is to keep it in the news cycle for relevance as data centers are hated by most citizens. They take away the common good from all of us with relentless surveillance... www.theguardian.com/technology/ 2...
-
@andyscollick
Andy Scollick
on bluesky
AI “security” is a sick joke. — If you use #AI you are making youself and others vulnerable. — It's only a matter of time before this costs lives - lots of lives.
-
NewsMax.com
Charlie McCarthy
on x
Researchers Hack OpenAI Systems Via Anthropic's Claude
-
@jeremiahdillon
Jeremiah Dillon
on x
If anyone has the sword, everyone needs the shield. OpenAI hacks Hugging Face: “sure, one of the most advanced labs with limitless resources can do this...
-
@cramforce
Malte Ubl
on x
When I might have sounded alarmist over the last few weeks, it was because I was aware @S1r1u5_'s excellent work here that is the perfect demonstration of our new reality: - There is a vulnerability in a random image codec library - This library is used by O(every app) - There ar…
-
@zackkorman
Zack Korman
on x
Worth mentioning that @S1r1u5_ has been trying unsuccessfully to get trusted access for cyber from OpenAI. They still don't have it. If having this level of access but not doing anything malicious doesn't earn that, nothing will.
-
@weezerosint
@weezerosint
on x
The bounty for this was only $6,500...
-
@r0bre
@r0bre
on x
Very cool research and exploit chain by @S1r1u5_ and @HacktronAI. Something interesting we're seeing here is that there's still a large gap between what skilled researchers + AI can do vs. general population + AI. They know what to point the AI at, where to keep digging, and have…
-
@nickadobos
Nick Dobos
on x
OpenAI was hacked via the exact library mentioned in the xkcd comic hahahaha The prophecy is fulfilled
-
@iminurputer
@iminurputer
on x
not even close to the most insane hack and they're not just 3 dudes damn the disrespect hacktron's security research team arguably one of the top teams in the world!
-
@mikeisaac
Rat King
on x
this is the stuff i am more concerned about in the immediate term rather than skynet three indie hackers (who have a track record of clever infiltration of companies and participating in lawful bug bounties) crack one AI lab using another Lab's model on a shoestring budget
-
@linchzhang
Linch
on x
OpenAI unilaterally implements “Total Research Transparency” from Plan A! 🎉🎉🎉
-
@isaacking314
Isaac King
on x
Even among organizations that take AI “seriously”, the general approach is still to treat it as a SaaS product. The security posture of the typical SaaS company is *incredibly* bad. Things like this are going to keep happening unless there is a fundamental shift in approach.
-
@florian_jue
Florian Juengermann
on x
The xkcd meme literally happened It will be a crazy couple of months for security. But I'm optimistic that we will be in a better place after this with democratized security intelligence.
-
@drelidavid
Dr. Eli David
on x
Now imagine what kind of ongoing 24/7 access to OpenAI and Anthropic enemy nations with sophisticated cyber capabilities have
-
@leahmcelrath
Leah McElrath
on x
Wild account of how a few white hats hacked OpenAI and could have easily hacked multiple other prominent platforms—worth reading the whole thread:
-
@artemr
Artem Russakovskii
on x
OpenAI got hacked. Thankfully, the hacker was a security researcher and not a nefarious party. This time. Kudos @S1r1u5_ @rootxharsh @HacktronAI.
-
@jessefelder.com
Jesse Felder
on bluesky
‘What kind of legal liability might an A.I. lab like OpenAI or Anthropic face if its products were to run amok and cause great harm?’ www.nytimes.com/2026/09/18/b... [image]
-
Aadityasinh Jadeja
Aadityasinh Jadeja
on linkedin
OpenAI got hacked and it started with an image upload. — Not the main OpenAI systems directly, though. It started from their community forum. …