/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Security researchers in OpenAI's bug bounty program hacked OpenAI in July and accessed its “monorepo” on GitHub, using Opus 4.8 for cybersecurity and Opus 5

Wall Street Journal Robert McMillan

Context & Ripple Effects

The disclosed bug-bounty exercise lands against a record of security incidents touching OpenAI’s internal information: reporting in 2024 described an early-2023 breach of its internal messaging systems, while July reporting said OpenAI models were implicated in a breach of Hugging Face. The new account of repository access shifts attention from model misuse in an external service to the identity and access controls around a leading lab’s own development environment.

It also gives operational weight to researchers’ argument that advanced coding models compress parts of exploit development; that remains their interpretation of the exercise, not a measure of autonomous attack capability.

First-order effects

  • OpenAI must treat access to its GitHub monorepo as an access-control and repository-security incident, reviewing the exploit path and any connected employee accounts or services reached during the authorized testing.
  • The researchers’ successful use of Opus 4.8 for cybersecurity and Opus 5 makes cyber-specific model access part of the security posture that OpenAI’s bug-bounty program has to evaluate.

Second-order effects

  • AI labs and enterprise GitHub users face pressure to test single-sign-on configurations and connected-service permissions against attackers assisted by capable coding models, rather than assessing those controls only against conventional manual workflows.
  • Bug-bounty programs gain a stronger case for evaluating full exploit chains, including how authorized researchers use models and tools after an initial foothold, instead of rewarding isolated vulnerability reports.

Third-order effects

  • If skilled researchers’ account that models reduce the scarce expertise needed for exploit development holds across more tests, software security shifts toward defending trusted identity and tool integrations against faster human-directed attack chains.
  • The incident points to operational AI assurance becoming inseparable from model deployment: labs will need to assess not only harmful outputs, but the practical security consequences of granting powerful models cyber and coding capabilities.

The trend: Cyber-capable coding models are turning identity, repository, and connected-tool controls into a more consequential attack surface for the AI labs that build them.

Discussion

  • NewsMax.com Charlie McCarthy on x
    Researchers Hack OpenAI Systems Via Anthropic's Claude
  • @s1r1u5_ @s1r1u5_ on x
    On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI's internal codebase . It took us <72h. 🧵
  • @andrewcurran_ Andrew Curran on x
    They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.
  • @r0bre @r0bre on x
    Very cool research and exploit chain by @S1r1u5_ and @HacktronAI. Something interesting we're seeing here is that there's still a large gap between what skilled researchers + AI can do vs. general population + AI. They know what to point the AI at, where to keep digging, and have…
  • @s1r1u5_ @s1r1u5_ on x
    Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits.  Work that once took months can now take days.  Even leading AI labs can be vulnerable.  Defenders need to fix the architecture, patch faster, and limit the blast radi…
  • @cramforce Malte Ubl on x
    When I might have sounded alarmist over the last few weeks, it was because I was aware @S1r1u5_'s excellent work here that is the perfect demonstration of our new reality: - There is a vulnerability in a random image codec library - This library is used by O(every app) - There ar…
  • @jeremiahdillon Jeremiah Dillon on x
    If anyone has the sword, everyone needs the shield. OpenAI hacks Hugging Face: “sure, one of the most advanced labs with limitless resources can do this...
  • @mikeisaac Rat King on x
    this is the stuff i am more concerned about in the immediate term rather than skynet three indie hackers (who have a track record of clever infiltration of companies and participating in lawful bug bounties) crack one AI lab using another Lab's model on a shoestring budget
  • @artemr Artem Russakovskii on x
    OpenAI got hacked. Thankfully, the hacker was a security researcher and not a nefarious party. This time. Kudos @S1r1u5_ @rootxharsh @HacktronAI.
  • @drelidavid Dr. Eli David on x
    Now imagine what kind of ongoing 24/7 access to OpenAI and Anthropic enemy nations with sophisticated cyber capabilities have
  • @iminurputer @iminurputer on x
    not even close to the most insane hack and they're not just 3 dudes damn the disrespect hacktron's security research team arguably one of the top teams in the world!
  • @isaacking314 Isaac King on x
    Even among organizations that take AI “seriously”, the general approach is still to treat it as a SaaS product. The security posture of the typical SaaS company is *incredibly* bad. Things like this are going to keep happening unless there is a fundamental shift in approach.
  • @weezerosint @weezerosint on x
    The bounty for this was only $6,500...
  • @linchzhang Linch on x
    OpenAI unilaterally implements “Total Research Transparency” from Plan A! 🎉🎉🎉
  • @florian_jue Florian Juengermann on x
    The xkcd meme literally happened It will be a crazy couple of months for security. But I'm optimistic that we will be in a better place after this with democratized security intelligence.
  • @leahmcelrath Leah McElrath on x
    Wild account of how a few white hats hacked OpenAI and could have easily hacked multiple other prominent platforms—worth reading the whole thread:
  • @zackkorman Zack Korman on x
    Worth mentioning that @S1r1u5_ has been trying unsuccessfully to get trusted access for cyber from OpenAI. They still don't have it. If having this level of access but not doing anything malicious doesn't earn that, nothing will.
  • @nickadobos Nick Dobos on x
    OpenAI was hacked via the exact library mentioned in the xkcd comic hahahaha The prophecy is fulfilled
  • @mikeisaac Rat King on x
    very detailed rundown from the hacker group here (which turned in the exploits to the companies) man.
  • @hlntnr Helen Toner on x
    One leeetle tiny flaw in the “we have to have better AI than China, therefore we have to rush ahead as fast as possible”: If you rush so much that your security is garbage and your increasingly advanced AI models are there for the taking by Chinese hackers, then you have uhhh not…
  • @jeffladish Jeffrey Ladish on x
    If they got full access to the monorepo, that means they could have downloaded OpenAI's entire code base
  • @garymarcus Gary Marcus on x
    Jeezus. OpenAI cannot be trusted with the safety of the world. They can't even keep their own servers secure.
  • @yuchenj_uw Yuchen Jin on x
    OK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo.  Their entire hacking cost less than $3000 in tokens.  Opus 4.8 strugg…
  • @enginoid Fred Jonsson on x
    They use an RCE to get into Discourse, where they presumably stole a token or cookie that had access to internal OpenAI systems. (It's not clear how they used the RCE.) That definitely sounds like misconfiguration of token issuance/authz or cookies, but it's not the root issue. E…
  • @reedalbergotti Reed Albergotti on x
    I actually think the question is not “what can a nation state do?” We already know nation states can hack pretty much anything, any time they want. The question is, “if three guys can do this, what happens if millions of people do this?”
  • @kpolley Kyle Polley on x
    Hacktron team is 10/10. Insanely talented group, AI alone could not have achieved this it required taste and true expertise
  • @tracewoodgrains Jack on x
    >$6,500 award that number is quite a bit smaller than I would have expected given the magnitude of the rest of this
  • @symbolsrsymbols @symbolsrsymbols on x
    Scary af
  • @aisafetymemes @aisafetymemes on x
    3 random dudes just hacked into OpenAI... now, imagine how easy it is for nation states The US does NOT “beat China
  • @notdeghost Robert Chen on x
    really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
  • @sydneyvonarx @sydneyvonarx on x
    People often talk about racing with China. If a bunch of randos can waltz in and steal all your algorithmic secrets (& a bunch of customer data?) with a couple days' work, you'll probably lose that race.
  • @justanotherlaw Lawrence Chan on x
    More details on the OpenAI hack here.
  • @s1r1u5_ @s1r1u5_ on x
    AI agents did a meaningful share of the exploit work. Opus 4.8 found the libheif vulnerability and built a partial exploit. Hours after Opus 5 launched, it adapted the exploit to Discourse and achieved RCE on our test instance.
  • @s1r1u5_ @s1r1u5_ on x
    To demonstrate impact while minimising exposure, we used one affected employee account connected to OpenAI's GitHub org. Codex created a harmless PR in their internal monorepo without us reading sensitive code. That proved to us that the access was real.
  • @s1r1u5_ @s1r1u5_ on x
    The second bug is more serious: an OpenAI SSO vulnerability. Using this flaw, we turned our Discourse forum exploit into access to ChatGPT and Codex accounts belonging to people who had signed into it, including OpenAI employees.
  • @s1r1u5_ @s1r1u5_ on x
    The image package libheif had a known vulnerability, fixed upstream, but the fix never flagged as security-relevant and was still present in Discourse. Uploading a HEIF file gave us RCE on the OpenAI forum https://community.openai.com/. https://github.com/...
  • @joshua_saxe Joshua Saxe on x
    Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) mode…
  • @justanotherlaw Lawrence Chan on x
    This is crazy. In late July, “three guys with Claude and Codex subscriptions” were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/...
  • Aadityasinh Jadeja Aadityasinh Jadeja on linkedin
    OpenAI got hacked and it started with an image upload.  —  Not the main OpenAI systems directly, though.  It started from their community forum. …
  • Ian Braddish Ian Braddish on linkedin
    The WSJ story about attackers using Claude to help find a path into OpenAI is a pretty good reminder that “security-relevant logs” are getting harder to define. …
  • Emil Protalinski Emil Protalinski on linkedin
    No, Anthropic didn't hack OpenAI.  —  Three security researchers participating in OpenAI's bug bounty program used Anthropic's tools to hack OpenAI (https://lnkd.in/g8kCN5ep …
  • Mohan Sri Rama Krishna Pedhapati Mohan Sri Rama Krishna Pedhapati on linkedin
    On July 25, we hacked OpenAI.  —  It took us less than 72 hours and we proved it with a PR in OpenAI's internal codebase. …
  • @bluntrochester.senate … Senator Lisa Blunt Rochester on bluesky
    Republicans control the House and the Senate - if they wanted, we could be taking action to respond to these alarming escalations right now.  —  Instead, House Republicans are headed home.  In this moment that requires real leadership, they're abandoning ship.
  • @jessefelder.com Jesse Felder on bluesky
    ‘What kind of legal liability might an A.I. lab like OpenAI or Anthropic face if its products were to run amok and cause great harm?’ www.nytimes.com/2026/09/18/b...  [image]
  • @ericjgeller.com Eric Geller on bluesky
    “'I don't think we are as strong as Chinese threat actors,' said Mohan Pedhapati, chief technology officer with Hacktron AI, the security firm that did the research.  'We're just three guys with Claude and Codex subscriptions.'”  —  www.wsj.com/tech/ai/hack...
  • @imgregory @imgregory on bluesky
    So what does this prove?  That the floundering Ai industry's current aim is to keep it in the news cycle for relevance as data centers are hated by most citizens.  They take away the common good from all of us with relentless surveillance...  www.theguardian.com/technology/ 2...
  • @andyscollick Andy Scollick on bluesky
    AI “security” is a sick joke.  —  If you use #AI you are making youself and others vulnerable.  —  It's only a matter of time before this costs lives - lots of lives.
  • @timkellogg.me Mr. Tim on bluesky
    Two weeks after the Huggingface incident, attackers broke into OpenAI's internal systems using Opus 5 and gained write access to their Git repos  —  www.wsj.com/tech/ai/hack...
  • @leahmcelrath Leah McElrath on bluesky
    ⚠️ Three white hats hacked OpenAI.  —  They used Anthropic's Claude, and it took them less than 72 hours.  —  They successfully accessed the OpenAI's internal monorepo (code repository).  —  OpenAI only awarded them $6,500 for revealing the vulnerability.
  • @hailey.at Hailey on bluesky
    opus 5 was able to assist with breaking into openai  —  paying a bounty of 6.5k is wild when you just got pwned with write access lol  —  www.hacktron.ai/blog/hacking...
  • @coolhand @coolhand on bluesky
    “The researchers can't say for certain what the OpenAI source code system was used for, but they said it was named, ‘Monorepo.’ Monorepo, according to people familiar with OpenAI's architecture, is a large software repository of OpenAI's algorithmic secrets.”  —  Oh my god, they …
  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    Team using Anthropic's Claude hacked into OpenAI's internal code repository.  Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host.  The stolen login tokens also worked on ChatGPT, including employees' accounts.  Reward: a $6,500 bug b…
  • r/slatestarcodex r on reddit
    Full monorepo access and RCE at OpenAI
  • r/singularity r on reddit
    Independent Security Researchers Used Anthropic's Claude to Break Into OpenAI
  • r/technology r on reddit
    Hackers Used Anthropic's Claude to Break Into OpenAI