Security researchers in OpenAI's bug bounty program hacked OpenAI in July and accessed its “monorepo” on GitHub, using Opus 4.8 for cybersecurity and Opus 5
Wall Street Journal Robert McMillan
Context & Ripple Effects
The disclosed bug-bounty exercise lands against a record of security incidents touching OpenAI’s internal information: reporting in 2024 described an early-2023 breach of its internal messaging systems, while July reporting said OpenAI models were implicated in a breach of Hugging Face. The new account of repository access shifts attention from model misuse in an external service to the identity and access controls around a leading lab’s own development environment.
It also gives operational weight to researchers’ argument that advanced coding models compress parts of exploit development; that remains their interpretation of the exercise, not a measure of autonomous attack capability.
First-order effects
- OpenAI must treat access to its GitHub monorepo as an access-control and repository-security incident, reviewing the exploit path and any connected employee accounts or services reached during the authorized testing.
- The researchers’ successful use of Opus 4.8 for cybersecurity and Opus 5 makes cyber-specific model access part of the security posture that OpenAI’s bug-bounty program has to evaluate.
Second-order effects
- AI labs and enterprise GitHub users face pressure to test single-sign-on configurations and connected-service permissions against attackers assisted by capable coding models, rather than assessing those controls only against conventional manual workflows.
- Bug-bounty programs gain a stronger case for evaluating full exploit chains, including how authorized researchers use models and tools after an initial foothold, instead of rewarding isolated vulnerability reports.
Third-order effects
- If skilled researchers’ account that models reduce the scarce expertise needed for exploit development holds across more tests, software security shifts toward defending trusted identity and tool integrations against faster human-directed attack chains.
- The incident points to operational AI assurance becoming inseparable from model deployment: labs will need to assess not only harmful outputs, but the practical security consequences of granting powerful models cyber and coding capabilities.
The trend: Cyber-capable coding models are turning identity, repository, and connected-tool controls into a more consequential attack surface for the AI labs that build them.
Related: Agentic attack surface · Trusted-tool boundary · Operational AI assurance · GitHub · OpenAI models implicated in Hugging Face breach · OpenAI internal messaging breach
Related Coverage
- Hacking OpenAI — A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories Hacktron AI · Rahul Maini
- The A.I. Industry's New Worry: ‘Liability Exposure’ New York Times
- Bug Hunters Used Claude to Hack OpenAI The Information · Rocket Drew
- Anthropic and OpenAI need truly independent safety evaluators, experts say in public letter CNBC · Jonathan Vanian
- OpenAI ‘ethically hacked’ with help of Anthropic's Claude chatbot The Guardian · Dan Milmo
- Researchers used Anthropic's Claude to hack into OpenAI TechCrunch
- Cybersecurity researchers gain access to OpenAI's GitHub repository using Claude SiliconANGLE · Maria Deutscher
- White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing TechRadar · Benedict Collins
- AI News: Anthropic's Claude Reportedly Used in OpenAI Breach The Coin Republic · Arnold Kirimi
- Researchers use AI to find widespread software decoder flaw CyberScoop · Djohnson
- Hackers breached OpenAI, adding to fever pitch of security and safety concerns NBC News · Kevin Collier
- Security Researchers Hacked OpenAI Using Anthropic's Claude PCMag · Bee Wertheimer
- More Than 100 AI Experts Sign a Letter Saying that OpenAI & Anthropic Need Independent AI Safety Evaluators International Business Times · Matias Civita
- Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours The Decoder · Matthias Bastian
- OpenAI hack: 3 Indian-origin researchers used Anthropic's Claude to breach systems The Indian Express
- Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours Gizmodo · Webb Wright
- OpenAI employee accounts breached with help from Anthropic's Claude Proactive · Angela Harmantas
- Security researchers used Claude to help them hack into OpenAI The Verge · Stevie Bonifield
- Security Researchers Use Anthropic's Claude to Penetrate OpenAI's Private Software Cache PYMNTS
- Over 100 AI experts are warning that safety evaluators aren't truly independent Quartz · Cris Tolomia
- Security researchers use Anthropic's Claude to reach OpenAI's internal code AI Policy Daily
- The OpenAI Hack Shows Why Every AI Connection Needs Limits The Neuron · Corey Noles
- Three guys used Claude and Codex to hack into OpenAI Metacurity · Cynthia B Brumfield
- Anthropic is using Claude to build the next generation of AI Straight Arrow · Shea Taylor
- AI-Built Exploit And Sign-In Flaw Opened Path To Internal OpenAI Code SecurityWeek · Eduard Kovacs
- OpenAI breached by researchers using Anthropic models Financial Times · Cristina Criddle
- ROFL! 😹 Hacking OpenAI: A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories #cybersec — https://www.hacktron.ai/... @kcarruthers@infosec.exchange
- A heap overflow and SSO misconfiguration to compromise OpenAI internal repos Hacker News
- Hacking OpenAI Lobsters
- Researchers used Claude to hack OpenAI Ars OpenForum
Discussion
-
NewsMax.com
Charlie McCarthy
on x
Researchers Hack OpenAI Systems Via Anthropic's Claude
-
@s1r1u5_
@s1r1u5_
on x
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI's internal codebase . It took us <72h. 🧵
-
@andrewcurran_
Andrew Curran
on x
They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.
-
@r0bre
@r0bre
on x
Very cool research and exploit chain by @S1r1u5_ and @HacktronAI. Something interesting we're seeing here is that there's still a large gap between what skilled researchers + AI can do vs. general population + AI. They know what to point the AI at, where to keep digging, and have…
-
@s1r1u5_
@s1r1u5_
on x
Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable. Defenders need to fix the architecture, patch faster, and limit the blast radi…
-
@cramforce
Malte Ubl
on x
When I might have sounded alarmist over the last few weeks, it was because I was aware @S1r1u5_'s excellent work here that is the perfect demonstration of our new reality: - There is a vulnerability in a random image codec library - This library is used by O(every app) - There ar…
-
@jeremiahdillon
Jeremiah Dillon
on x
If anyone has the sword, everyone needs the shield. OpenAI hacks Hugging Face: “sure, one of the most advanced labs with limitless resources can do this...
-
@mikeisaac
Rat King
on x
this is the stuff i am more concerned about in the immediate term rather than skynet three indie hackers (who have a track record of clever infiltration of companies and participating in lawful bug bounties) crack one AI lab using another Lab's model on a shoestring budget
-
@artemr
Artem Russakovskii
on x
OpenAI got hacked. Thankfully, the hacker was a security researcher and not a nefarious party. This time. Kudos @S1r1u5_ @rootxharsh @HacktronAI.
-
@drelidavid
Dr. Eli David
on x
Now imagine what kind of ongoing 24/7 access to OpenAI and Anthropic enemy nations with sophisticated cyber capabilities have
-
@iminurputer
@iminurputer
on x
not even close to the most insane hack and they're not just 3 dudes damn the disrespect hacktron's security research team arguably one of the top teams in the world!
-
@isaacking314
Isaac King
on x
Even among organizations that take AI “seriously”, the general approach is still to treat it as a SaaS product. The security posture of the typical SaaS company is *incredibly* bad. Things like this are going to keep happening unless there is a fundamental shift in approach.
-
@weezerosint
@weezerosint
on x
The bounty for this was only $6,500...
-
@linchzhang
Linch
on x
OpenAI unilaterally implements “Total Research Transparency” from Plan A! 🎉🎉🎉
-
@florian_jue
Florian Juengermann
on x
The xkcd meme literally happened It will be a crazy couple of months for security. But I'm optimistic that we will be in a better place after this with democratized security intelligence.
-
@leahmcelrath
Leah McElrath
on x
Wild account of how a few white hats hacked OpenAI and could have easily hacked multiple other prominent platforms—worth reading the whole thread:
-
@zackkorman
Zack Korman
on x
Worth mentioning that @S1r1u5_ has been trying unsuccessfully to get trusted access for cyber from OpenAI. They still don't have it. If having this level of access but not doing anything malicious doesn't earn that, nothing will.
-
@nickadobos
Nick Dobos
on x
OpenAI was hacked via the exact library mentioned in the xkcd comic hahahaha The prophecy is fulfilled
-
@mikeisaac
Rat King
on x
very detailed rundown from the hacker group here (which turned in the exploits to the companies) man.
-
@hlntnr
Helen Toner
on x
One leeetle tiny flaw in the “we have to have better AI than China, therefore we have to rush ahead as fast as possible”: If you rush so much that your security is garbage and your increasingly advanced AI models are there for the taking by Chinese hackers, then you have uhhh not…
-
@jeffladish
Jeffrey Ladish
on x
If they got full access to the monorepo, that means they could have downloaded OpenAI's entire code base
-
@garymarcus
Gary Marcus
on x
Jeezus. OpenAI cannot be trusted with the safety of the world. They can't even keep their own servers secure.
-
@yuchenj_uw
Yuchen Jin
on x
OK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 strugg…
-
@enginoid
Fred Jonsson
on x
They use an RCE to get into Discourse, where they presumably stole a token or cookie that had access to internal OpenAI systems. (It's not clear how they used the RCE.) That definitely sounds like misconfiguration of token issuance/authz or cookies, but it's not the root issue. E…
-
@reedalbergotti
Reed Albergotti
on x
I actually think the question is not “what can a nation state do?” We already know nation states can hack pretty much anything, any time they want. The question is, “if three guys can do this, what happens if millions of people do this?”
-
@kpolley
Kyle Polley
on x
Hacktron team is 10/10. Insanely talented group, AI alone could not have achieved this it required taste and true expertise
-
@tracewoodgrains
Jack
on x
>$6,500 award that number is quite a bit smaller than I would have expected given the magnitude of the rest of this
-
@symbolsrsymbols
@symbolsrsymbols
on x
Scary af
-
@aisafetymemes
@aisafetymemes
on x
3 random dudes just hacked into OpenAI... now, imagine how easy it is for nation states The US does NOT “beat China
-
@notdeghost
Robert Chen
on x
really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
-
@sydneyvonarx
@sydneyvonarx
on x
People often talk about racing with China. If a bunch of randos can waltz in and steal all your algorithmic secrets (& a bunch of customer data?) with a couple days' work, you'll probably lose that race.
-
@justanotherlaw
Lawrence Chan
on x
More details on the OpenAI hack here.
-
@s1r1u5_
@s1r1u5_
on x
AI agents did a meaningful share of the exploit work. Opus 4.8 found the libheif vulnerability and built a partial exploit. Hours after Opus 5 launched, it adapted the exploit to Discourse and achieved RCE on our test instance.
-
@s1r1u5_
@s1r1u5_
on x
To demonstrate impact while minimising exposure, we used one affected employee account connected to OpenAI's GitHub org. Codex created a harmless PR in their internal monorepo without us reading sensitive code. That proved to us that the access was real.
-
@s1r1u5_
@s1r1u5_
on x
The second bug is more serious: an OpenAI SSO vulnerability. Using this flaw, we turned our Discourse forum exploit into access to ChatGPT and Codex accounts belonging to people who had signed into it, including OpenAI employees.
-
@s1r1u5_
@s1r1u5_
on x
The image package libheif had a known vulnerability, fixed upstream, but the fix never flagged as security-relevant and was still present in Discourse. Uploading a HEIF file gave us RCE on the OpenAI forum https://community.openai.com/. https://github.com/...
-
@joshua_saxe
Joshua Saxe
on x
Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) mode…
-
@justanotherlaw
Lawrence Chan
on x
This is crazy. In late July, “three guys with Claude and Codex subscriptions” were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/...
-
Aadityasinh Jadeja
Aadityasinh Jadeja
on linkedin
OpenAI got hacked and it started with an image upload. — Not the main OpenAI systems directly, though. It started from their community forum. …
-
Ian Braddish
Ian Braddish
on linkedin
The WSJ story about attackers using Claude to help find a path into OpenAI is a pretty good reminder that “security-relevant logs” are getting harder to define. …
-
Emil Protalinski
Emil Protalinski
on linkedin
No, Anthropic didn't hack OpenAI. — Three security researchers participating in OpenAI's bug bounty program used Anthropic's tools to hack OpenAI (https://lnkd.in/g8kCN5ep …
-
Mohan Sri Rama Krishna Pedhapati
Mohan Sri Rama Krishna Pedhapati
on linkedin
On July 25, we hacked OpenAI. — It took us less than 72 hours and we proved it with a PR in OpenAI's internal codebase. …
-
@bluntrochester.senate …
Senator Lisa Blunt Rochester
on bluesky
Republicans control the House and the Senate - if they wanted, we could be taking action to respond to these alarming escalations right now. — Instead, House Republicans are headed home. In this moment that requires real leadership, they're abandoning ship.
-
@jessefelder.com
Jesse Felder
on bluesky
‘What kind of legal liability might an A.I. lab like OpenAI or Anthropic face if its products were to run amok and cause great harm?’ www.nytimes.com/2026/09/18/b... [image]
-
@ericjgeller.com
Eric Geller
on bluesky
“'I don't think we are as strong as Chinese threat actors,' said Mohan Pedhapati, chief technology officer with Hacktron AI, the security firm that did the research. 'We're just three guys with Claude and Codex subscriptions.'” — www.wsj.com/tech/ai/hack...
-
@imgregory
@imgregory
on bluesky
So what does this prove? That the floundering Ai industry's current aim is to keep it in the news cycle for relevance as data centers are hated by most citizens. They take away the common good from all of us with relentless surveillance... www.theguardian.com/technology/ 2...
-
@andyscollick
Andy Scollick
on bluesky
AI “security” is a sick joke. — If you use #AI you are making youself and others vulnerable. — It's only a matter of time before this costs lives - lots of lives.
-
@timkellogg.me
Mr. Tim
on bluesky
Two weeks after the Huggingface incident, attackers broke into OpenAI's internal systems using Opus 5 and gained write access to their Git repos — www.wsj.com/tech/ai/hack...
-
@leahmcelrath
Leah McElrath
on bluesky
⚠️ Three white hats hacked OpenAI. — They used Anthropic's Claude, and it took them less than 72 hours. — They successfully accessed the OpenAI's internal monorepo (code repository). — OpenAI only awarded them $6,500 for revealing the vulnerability.
-
@hailey.at
Hailey
on bluesky
opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol — www.hacktron.ai/blog/hacking...
-
@coolhand
@coolhand
on bluesky
“The researchers can't say for certain what the OpenAI source code system was used for, but they said it was named, ‘Monorepo.’ Monorepo, according to people familiar with OpenAI's architecture, is a large software repository of OpenAI's algorithmic secrets.” — Oh my god, they …
-
@LukaszOlejnik@mastodon.social
Lukasz Olejnik
on mastodon
Team using Anthropic's Claude hacked into OpenAI's internal code repository. Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host. The stolen login tokens also worked on ChatGPT, including employees' accounts. Reward: a $6,500 bug b…
-
r/slatestarcodex
r
on reddit
Full monorepo access and RCE at OpenAI
-
r/singularity
r
on reddit
Independent Security Researchers Used Anthropic's Claude to Break Into OpenAI
-
r/technology
r
on reddit
Hackers Used Anthropic's Claude to Break Into OpenAI