Hacktron Breached OpenAI GitHub in Under 72 Hours via HEIF Flaw
Updated
Updated · The Verge · Sep 18
Hacktron Breached OpenAI GitHub in Under 72 Hours via HEIF Flaw
3 articles · Updated · The Verge · Sep 18
Summary
Three Hacktron researchers said they reached OpenAI employee accounts and the company's GitHub “Monorepo” in less than 72 hours, then sent a pull request from an employee Codex account to prove access.
The breach used a corrupted HEIF image to exploit Discourse forum software, with Anthropic’s Claude Opus 5 helping achieve remote code execution on Discourse Cloud by the morning after its July 24 launch.
Hacktron said the same “HEIF Heist” technique could be adapted to targets including Slack, Meta, GitHub Enterprise and Shopify in one to two days for under $3,000 in tokens; Shopify was the only target it believes detected it.
Discourse and OpenAI have since fixed the vulnerabilities, and OpenAI paid Hacktron $6,500 in bug-bounty rewards, underscoring how cheaply AI-assisted exploit development can expose major platforms.