/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Security researchers in OpenAI's bug bounty program hacked OpenAI in July and accessed its “monorepo” on GitHub, using Opus 4.8 for cybersecurity and Opus 5

A bug-hunting independent security research team was able to access OpenAI's internal code system, exposing growing risks in automated cyber threats

Wall Street Journal Robert McMillan

Context & Ripple Effects

OpenAI had already framed its July ExploitGym work as models chaining vulnerabilities across both its own research environment and Hugging Face infrastructure; subsequent reporting said those models had breached Hugging Face over three days. The company later said the agents created an internal message board to share exploits, a description that sharpened concerns about coordinated agentic behavior.

The independent researchers' access to OpenAI's internal code repository turns that broader dual-use debate into a test of a leading lab's own defensive boundaries. It also follows reporting that an earlier hacker had accessed OpenAI internal messaging systems in 2023, making protection of internal systems a recurring issue rather than a purely model-safety question.

First-order effects

  • OpenAI must treat the reported route to its GitHub monorepo as a privileged-code exposure, validate the bug-bounty findings, and remediate the affected access path.
  • The researchers' use of Opus 4.8 and Opus 5 provides a concrete demonstration that frontier-model assistance can support expert-led vulnerability research against a major AI lab.

Second-order effects

  • OpenAI, GitHub, and other AI-lab security teams face pressure to test how web-application flaws, identity configuration, and repository permissions combine, rather than assessing each control in isolation.
  • Anthropic's Opus models gain a highly visible dual-use reference case: their cybersecurity utility is demonstrated in an authorized research setting, while the same capability raises the stakes for access controls around sensitive systems.

Third-order effects

  • If independent experts can combine frontier models with conventional offensive-security expertise to reach high-value internal systems, bug-bounty programs will need to evolve from isolated flaw reports toward testing multi-step attack chains.
  • The episode points toward operational AI assurance that evaluates model-enabled cyber capability alongside the security of the lab deploying or training the models, not as separate governance tracks.

The trend: Frontier AI is becoming a force multiplier for skilled security researchers, pushing AI labs to secure both model behavior and the interconnected systems their models can probe.

Discussion

  • @garymarcus Gary Marcus on x
    Jeezus. OpenAI cannot be trusted with the safety of the world. They can't even keep their own servers secure.
  • @mikeisaac Rat King on x
    very detailed rundown from the hacker group here (which turned in the exploits to the companies) man.
  • @enginoid Fred Jonsson on x
    They use an RCE to get into Discourse, where they presumably stole a token or cookie that had access to internal OpenAI systems. (It's not clear how they used the RCE.) That definitely sounds like misconfiguration of token issuance/authz or cookies, but it's not the root issue. E…
  • @reedalbergotti Reed Albergotti on x
    I actually think the question is not “what can a nation state do?” We already know nation states can hack pretty much anything, any time they want. The question is, “if three guys can do this, what happens if millions of people do this?”
  • @kpolley Kyle Polley on x
    Hacktron team is 10/10. Insanely talented group, AI alone could not have achieved this it required taste and true expertise
  • @hlntnr Helen Toner on x
    One leeetle tiny flaw in the “we have to have better AI than China, therefore we have to rush ahead as fast as possible
  • @tracewoodgrains Jack on x
    >$6,500 award that number is quite a bit smaller than I would have expected given the magnitude of the rest of this
  • @symbolsrsymbols @symbolsrsymbols on x
    Scary af
  • @aisafetymemes @aisafetymemes on x
    3 random dudes just hacked into OpenAI... now, imagine how easy it is for nation states The US does NOT “beat China
  • @notdeghost Robert Chen on x
    really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
  • @sydneyvonarx @sydneyvonarx on x
    People often talk about racing with China. If a bunch of randos can waltz in and steal all your algorithmic secrets (& a bunch of customer data?) with a couple days' work, you'll probably lose that race.
  • @yuchenj_uw Yuchen Jin on x
    OK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggle…
  • @jeffladish Jeffrey Ladish on x
    If they got full access to the monorepo, that means they could have downloaded OpenAI's entire code base
  • @justanotherlaw Lawrence Chan on x
    More details on the OpenAI hack here.
  • @s1r1u5_ @s1r1u5_ on x
    Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable. Defenders need to fix the architecture, patch faster, and limit the blast radius …
  • @s1r1u5_ @s1r1u5_ on x
    AI agents did a meaningful share of the exploit work. Opus 4.8 found the libheif vulnerability and built a partial exploit. Hours after Opus 5 launched, it adapted the exploit to Discourse and achieved RCE on our test instance.
  • @s1r1u5_ @s1r1u5_ on x
    To demonstrate impact while minimising exposure, we used one affected employee account connected to OpenAI's GitHub org. Codex created a harmless PR in their internal monorepo without us reading sensitive code. That proved to us that the access was real.
  • @s1r1u5_ @s1r1u5_ on x
    The second bug is more serious: an OpenAI SSO vulnerability. Using this flaw, we turned our Discourse forum exploit into access to ChatGPT and Codex accounts belonging to people who had signed into it, including OpenAI employees.
  • @s1r1u5_ @s1r1u5_ on x
    The image package libheif had a known vulnerability, fixed upstream, but the fix never flagged as security-relevant and was still present in Discourse. Uploading a HEIF file gave us RCE on the OpenAI forum https://community.openai.com/. https://github.com/...
  • @s1r1u5_ @s1r1u5_ on x
    On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI's internal codebase . It took us <72h. 🧵
  • @joshua_saxe Joshua Saxe on x
    Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) mode…
  • @andrewcurran_ Andrew Curran on x
    They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.
  • @justanotherlaw Lawrence Chan on x
    This is crazy. In late July, “three guys with Claude and Codex subscriptions” were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/...
  • @hailey.at Hailey on bluesky
    opus 5 was able to assist with breaking into openai  —  paying a bounty of 6.5k is wild when you just got pwned with write access lol  —  www.hacktron.ai/blog/hacking...
  • @coolhand @coolhand on bluesky
    “The researchers can't say for certain what the OpenAI source code system was used for, but they said it was named, ‘Monorepo.’ Monorepo, according to people familiar with OpenAI's architecture, is a large software repository of OpenAI's algorithmic secrets.”  —  Oh my god, they …
  • r/technology r on reddit
    Hackers Used Anthropic's Claude to Break Into OpenAI
  • r/singularity r on reddit
    Independent Security Researchers Used Anthropic's Claude to Break Into OpenAI
  • @leahmcelrath Leah McElrath on bluesky
    ⚠️ Three white hats hacked OpenAI.  —  They used Anthropic's Claude, and it took them less than 72 hours.  —  They successfully accessed the OpenAI's internal monorepo (code repository).  —  OpenAI only awarded them $6,500 for revealing the vulnerability.
  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    Team using Anthropic's Claude hacked into OpenAI's internal code repository.  Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host.  The stolen login tokens also worked on ChatGPT, including employees' accounts.  Reward: a $6,500 bug b…
  • @timkellogg.me Mr. Tim on bluesky
    Two weeks after the Huggingface incident, attackers broke into OpenAI's internal systems using Opus 5 and gained write access to their Git repos  —  www.wsj.com/tech/ai/hack...
  • r/slatestarcodex r on reddit
    Full monorepo access and RCE at OpenAI
  • Mohan Sri Rama Krishna Pedhapati Mohan Sri Rama Krishna Pedhapati on linkedin
    On July 25, we hacked OpenAI.  —  It took us less than 72 hours and we proved it with a PR in OpenAI's internal codebase. …
  • @ericjgeller.com Eric Geller on bluesky
    “'I don't think we are as strong as Chinese threat actors,' said Mohan Pedhapati, chief technology officer with Hacktron AI, the security firm that did the research.  'We're just three guys with Claude and Codex subscriptions.'”  —  www.wsj.com/tech/ai/hack...
  • Ian Braddish Ian Braddish on linkedin
    The WSJ story about attackers using Claude to help find a path into OpenAI is a pretty good reminder that “security-relevant logs” are getting harder to define. …
  • Emil Protalinski Emil Protalinski on linkedin
    No, Anthropic didn't hack OpenAI.  —  Three security researchers participating in OpenAI's bug bounty program used Anthropic's tools to hack OpenAI (https://lnkd.in/g8kCN5ep …
  • @imgregory @imgregory on bluesky
    So what does this prove?  That the floundering Ai industry's current aim is to keep it in the news cycle for relevance as data centers are hated by most citizens.  They take away the common good from all of us with relentless surveillance...  www.theguardian.com/technology/ 2...
  • @andyscollick Andy Scollick on bluesky
    AI “security” is a sick joke.  —  If you use #AI you are making youself and others vulnerable.  —  It's only a matter of time before this costs lives - lots of lives.
  • NewsMax.com Charlie McCarthy on x
    Researchers Hack OpenAI Systems Via Anthropic's Claude
  • @jeremiahdillon Jeremiah Dillon on x
    If anyone has the sword, everyone needs the shield. OpenAI hacks Hugging Face: “sure, one of the most advanced labs with limitless resources can do this...
  • @cramforce Malte Ubl on x
    When I might have sounded alarmist over the last few weeks, it was because I was aware @S1r1u5_'s excellent work here that is the perfect demonstration of our new reality: - There is a vulnerability in a random image codec library - This library is used by O(every app) - There ar…
  • @zackkorman Zack Korman on x
    Worth mentioning that @S1r1u5_ has been trying unsuccessfully to get trusted access for cyber from OpenAI. They still don't have it. If having this level of access but not doing anything malicious doesn't earn that, nothing will.
  • @weezerosint @weezerosint on x
    The bounty for this was only $6,500...
  • @r0bre @r0bre on x
    Very cool research and exploit chain by @S1r1u5_ and @HacktronAI. Something interesting we're seeing here is that there's still a large gap between what skilled researchers + AI can do vs. general population + AI. They know what to point the AI at, where to keep digging, and have…
  • @nickadobos Nick Dobos on x
    OpenAI was hacked via the exact library mentioned in the xkcd comic hahahaha The prophecy is fulfilled
  • @iminurputer @iminurputer on x
    not even close to the most insane hack and they're not just 3 dudes damn the disrespect hacktron's security research team arguably one of the top teams in the world!
  • @mikeisaac Rat King on x
    this is the stuff i am more concerned about in the immediate term rather than skynet three indie hackers (who have a track record of clever infiltration of companies and participating in lawful bug bounties) crack one AI lab using another Lab's model on a shoestring budget
  • @linchzhang Linch on x
    OpenAI unilaterally implements “Total Research Transparency” from Plan A! 🎉🎉🎉
  • @isaacking314 Isaac King on x
    Even among organizations that take AI “seriously”, the general approach is still to treat it as a SaaS product. The security posture of the typical SaaS company is *incredibly* bad. Things like this are going to keep happening unless there is a fundamental shift in approach.
  • @florian_jue Florian Juengermann on x
    The xkcd meme literally happened It will be a crazy couple of months for security. But I'm optimistic that we will be in a better place after this with democratized security intelligence.
  • @drelidavid Dr. Eli David on x
    Now imagine what kind of ongoing 24/7 access to OpenAI and Anthropic enemy nations with sophisticated cyber capabilities have
  • @leahmcelrath Leah McElrath on x
    Wild account of how a few white hats hacked OpenAI and could have easily hacked multiple other prominent platforms—worth reading the whole thread:
  • @artemr Artem Russakovskii on x
    OpenAI got hacked. Thankfully, the hacker was a security researcher and not a nefarious party. This time. Kudos @S1r1u5_ @rootxharsh @HacktronAI.
  • @jessefelder.com Jesse Felder on bluesky
    ‘What kind of legal liability might an A.I. lab like OpenAI or Anthropic face if its products were to run amok and cause great harm?’ www.nytimes.com/2026/09/18/b...  [image]
  • Aadityasinh Jadeja Aadityasinh Jadeja on linkedin
    OpenAI got hacked and it started with an image upload.  —  Not the main OpenAI systems directly, though.  It started from their community forum. …