AIToday
Large Language ModelsAI Safety & AlignmentTHE DECODERPublished: Sep 19, 2026, 04:00 JST

Claude Opus 5 used to breach OpenAI forum in under 72 hours

Claude Opus 5 used to breach OpenAI forum in under 72 hours

3 Key Points

  1. What happened

    Hacktron researchers chained two flaws in OpenAI's community forum — an unpatched libheif image library and a misconfigured SSO — to reach employees' ChatGPT and Codex accounts and an internal GitHub repository.

  2. Why it matters

    Attackers proved a commercial AI model can turn a known but unpatched bug into a working exploit, so companies sitting on available fixes may be exposed to far cheaper attacks than before.

  3. What to watch

    Only Shopify noticed the activity across the researchers' wider targets, so the real test is whether other firms detect similar campaigns. Watch whether Debian packages like the forum's get patched promptly.

WHO IT HITSThis lands hardest on security and IT teams at companies that run login services, SSO, or third-party forum software, where an unpatched library or a misconfigured sign-on can now be chained by a small, low-budget team using AI models.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

OpenAI is getting a taste of its own medicine, as the article puts it: after inadvertently letting agents hack their way across the internet for months, the company has now been hacked with AI's help. The intrusion ran through community.openai.com, and anyone who had used "Sign in with OpenAI" there was potentially affected, since users can connect GitHub, Slack, and email to Codex and ChatGPT. The researchers used an employee's Codex account to create a harmless pull request in the internal monorepo to prove access, and say they did not view any sensitive data.

Two separate weaknesses made the chain possible. The first was in libheif, the library the forum used to process uploaded HEIC images; a fix had been available in the original source code for a year, but the Debian packages on the forum still lacked it. The second was a misconfiguration in OpenAI's central SSO system, which let anyone controlling the forum server impersonate active members and take over their ChatGPT and Codex accounts. The researchers say the flaw extended beyond the forum to any compromised service using OpenAI login.

The wider "HEIF Heist" investigation, covering Slack, Meta, GitHub Enterprise and other targets, is where the stakes become clearer. Three people spent two months and less than $3,000 on AI, and only Shopify noticed the activity despite thousands of image uploads and repeated crashes in image processing. Hacktron argues that threat models must reflect how cheap attacks have become, since complexity no longer shields companies the way it once did. Whether that argument changes how other firms prioritize known-but-unpatched bugs in their own stacks is likely to depend on how quickly similar scans surface elsewhere.

FAQ
How did the researchers get in?
They chained two flaws in OpenAI's community forum: an outdated libheif image library and a misconfiguration in OpenAI's single sign-on (SSO) system that let them impersonate forum members.
How much did the AI-assisted project cost?
Three people carried out the wider "HEIF Heist" project over two months and spent less than $3,000 on AI, adapting the attack to each new target in one to two days.
Was Claude Opus 4.8 able to do the same?
No. Opus 4.8 built a working exploit only with ASLR disabled. After Opus 5 shipped on July 24, it produced a working exploit for a local Mac within three hours.

Also reported by Ars Technica AI, TechCrunch AI

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Prism ML shrinks Qwen3.8 into 5.9GB Bonsai 2 27BSiliconANGLE AI · 1h ago
  • CoreWeave's first user conference set for Sept. 30-Oct. 1SiliconANGLE AI · 1h ago
  • HarnessRouter standardizes agent runs via one protocolDaily Dose of Data Science · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleSoftBank to buy Robotics and AI Institute from Hyundai