Updated
Updated · The Verge · Sep 18
Hacktron Breached OpenAI GitHub in Under 72 Hours via HEIF Flaw
Updated
Updated · The Verge · Sep 18

Hacktron Breached OpenAI GitHub in Under 72 Hours via HEIF Flaw

3 articles · Updated · The Verge · Sep 18

Summary

  • Three Hacktron researchers said they reached OpenAI employee accounts and the company's GitHub “Monorepo” in less than 72 hours, then sent a pull request from an employee Codex account to prove access.
  • The breach used a corrupted HEIF image to exploit Discourse forum software, with Anthropic’s Claude Opus 5 helping achieve remote code execution on Discourse Cloud by the morning after its July 24 launch.
  • Hacktron said the same “HEIF Heist” technique could be adapted to targets including Slack, Meta, GitHub Enterprise and Shopify in one to two days for under $3,000 in tokens; Shopify was the only target it believes detected it.
  • Discourse and OpenAI have since fixed the vulnerabilities, and OpenAI paid Hacktron $6,500 in bug-bounty rewards, underscoring how cheaply AI-assisted exploit development can expose major platforms.

Insights

Why did OpenAI pay merely $6,500 after a rival AI successfully hijacked their employee accounts and infiltrated their internal systems?
How did an AI agent turn a simple forum image upload into a backdoor to OpenAI's most guarded internal code?
If AI can autonomously chain vulnerabilities to hack a leading AI lab in under 72 hours, is any enterprise network truly secure?