Hacktron Uses Claude Opus 5 to Reach OpenAI’s Internal GitHub
United States

Leon Neal/Getty Images/Getty
What Happened
What Happened
Where Sources Agree
- arrows_inputBreach Execution Path: Coverage broadly details how Hacktron researchers used Anthropic’s Claude to chain a forum image-processing vulnerability with an SSO flaw, enabling unauthorized access to OpenAI internal systems within 72 hours, per Hacktron’s technical disclosure.
- arrows_inputAI-Accelerated Exploit Development: Outlets generally confirm that Claude Opus 4.8 failed to generate a reliable exploit, with the newer Opus 5 model producing a working version within hours, according to Hacktron researchers.
- arrows_inputOpenAI Response and Bounty: Coverage largely emphasizes that OpenAI addressed the breach by fixing the single sign-on issue within 14 hours, revoking affected tokens, and issuing a $6,500 bounty to the researchers, according to official OpenAI statements.
Where Sources Disagree
- arrows_outputClaude Model Access: Some reports state researchers used the standard Claude Opus 5 model to develop their exploit. In contrast, other outlets specify that the team utilized a special, restricted version of Claude provided by Anthropic specifically for authorized cybersecurity researchers.
- arrows_outputBounty Program Attribution: Reports vary slightly in their description of the bounty process; while some outlets specify that OpenAI paid the reward through its Bugcrowd program, others describe the payment generally as part of OpenAI's bounty program without naming the specific platform.
- arrows_outputModel Restriction Context: Reports vary slightly in their technical detail, with some outlets noting that the more advanced 'Mythos 5' model, which is restricted to vetted organizations, was not involved in the breach.
Timeline
September 18, 2026
Public Disclosure And Aftermath: The researchers published a technical account in September and media coverage in mid-September documented that Hacktron had demonstrated access to an OpenAI employee's ChatGPT/Codex account and opened a benign pull request in the internal openai/openai monorepo; OpenAI says the issues are resolved and paid the team $6,500. The incident spurred broader debate about AI-assisted exploit development and enterprise security.
July 25, 2026
Reported And Patched; Tokens Revoked: Hacktron reported the findings through OpenAI's Bugcrowd program (reported July 25); OpenAI confirmed its side was fixed roughly 14 hours after notification, narrowed permissions and revoked affected community sign-in tokens, and Discourse issued a patch (fix deployed around July 27). OpenAI later paid the researchers a $6,500 bounty.
July 25, 2026
Opus 5 Generated Working Exploit: After Anthropic released Claude Opus 5 on July 24, Hacktron switched models and the newer Opus 5 produced a working remote-code-execution exploit within hours, which the researchers adapted to Discourse's x86-64/jemalloc environment and used to achieve RCE and later access an OpenAI employee account. Hacktron says the full path from discovery to repo access took under 72 hours.
Perspectives and Debates
Summary by Ground AI
Sources
See All 147A varied selection of sources chosen by Ground to reflect the diversity of this story’s coverage.
Most Written About
The stories getting the most coverage from the last 24 hours
Timeline
September 18, 2026
Public Disclosure And Aftermath: The researchers published a technical account in September and media coverage in mid-September documented that Hacktron had demonstrated access to an OpenAI employee's ChatGPT/Codex account and opened a benign pull request in the internal openai/openai monorepo; OpenAI says the issues are resolved and paid the team $6,500. The incident spurred broader debate about AI-assisted exploit development and enterprise security.
July 25, 2026
Reported And Patched; Tokens Revoked: Hacktron reported the findings through OpenAI's Bugcrowd program (reported July 25); OpenAI confirmed its side was fixed roughly 14 hours after notification, narrowed permissions and revoked affected community sign-in tokens, and Discourse issued a patch (fix deployed around July 27). OpenAI later paid the researchers a $6,500 bounty.
July 25, 2026
Opus 5 Generated Working Exploit: After Anthropic released Claude Opus 5 on July 24, Hacktron switched models and the newer Opus 5 produced a working remote-code-execution exploit within hours, which the researchers adapted to Discourse's x86-64/jemalloc environment and used to achieve RCE and later access an OpenAI employee account. Hacktron says the full path from discovery to repo access took under 72 hours.













