At the end of July, three people from the security company Hacktron AI gained access to OpenAI's internal systems. They started with an ordinary photo uploaded to a discussion forum and ended up in the company's source code repository, where they had write access. They were aided by Claude, a tool from Anthropic, which is a direct competitor to OpenAI. They published the entire process last Thursday, OpenAI paid them $6,500 for the discovery, and the vulnerabilities have since been patched.
From a Photo on a Forum to Company Code
The way in led through OpenAI's public discussion forum. Anyone can upload an image there, and the forum automatically converts it into a common format so that it displays properly. The flaw was hidden in this conversion process. When the researchers uploaded a specially modified photo in the format commonly used by iPhones, the image-processing program became confused, allowing them to gain control of the server on which the forum was running. What made matters worse was that the creators of the program had fixed the flaw several months earlier. However, no one had officially entered it into the public database of security vulnerabilities monitored by the entire industry. This was probably why the forum continued to run an old, vulnerable version.
Once inside, the team encountered a second problem. A forum login was also valid for ChatGPT and the Codex developer tool, making it possible to take over other people's accounts, including employee accounts. In this way, they gained access to the account of an OpenAI employee who had connected Codex to the company's code repository on GitHub. There, they found a section called Monorepo. According to Wall Street Journal sources, it is a component that helps OpenAI's models run faster. The researchers did not download anything; they only submitted a harmless proposed code change to the repository to demonstrate how far they had gotten. They said that the scope of what they could theoretically have accessed was enormous. According to them, fewer than 72 hours passed between the initial breach and the confirmation of access.
They then called OpenAI and the forum operator. A fix was released on July 27. OpenAI spokesperson Drew Pusateri said that the company thanked the researchers for reaching out and sharing their findings, and that the issue had been resolved. OpenAI also invalidated the affected login sessions and restricted their permissions.
The Weaker Model Failed, but the Newer One Succeeded
The researchers worked with a special version of the Claude Opus 4.8 model that Anthropic makes available only to vetted security experts. However, the model repeatedly failed. They described how, despite repeated attempts, it struggled in vain to produce working code that could exploit the flaw. The breakthrough came overnight when Anthropic released Opus 5. The team gave it exactly the same task, and within a few hours it was done. They noted that each new model is becoming increasingly capable.
According to their report, the actual breach of OpenAI required a few days of work by a computer assistant and only a few hours of human time. It was not an attack, but part of a program in which OpenAI pays for reported vulnerabilities. It was part of research that Hacktron called HEIF Heist, in which it examined how various services handle image files. Using the same method, it also found vulnerabilities at Slack, Zoom, Meta, and other companies. The work took two months, involved three people, and cost them less than three thousand dollars in total for model usage.
Why the Media Made It a Major Story
The appeal of the story lies mainly in the balance of power. Three people with an ordinary subscription gained access to a company that develops artificial intelligence itself and certainly has money for security.
Matt Fredrikson, head of the security company Gray Swan, summed it up by saying that for two hundred dollars a month, anyone can use these tools and break into a company like OpenAI. He added that if it can happen to them—and he does not think they have been neglecting security lately—it can happen to anyone. A natural question then appeared on social media: if a three-person team can do this, what can a state or a large organization accomplish?
Hacktron founder Mohan Pedhapati wrote on X that artificial intelligence reduces the amount of scarce expertise needed for someone to exploit a vulnerability, and that work that used to take months now takes days. At the end of its report, the team wrote that software had long been protected by its own complexity, and that artificial intelligence is now dismantling that protection by replacing expertise with computing power.
The case also affected the debate over what should and should not be made publicly available. Opus 5, which ultimately cracked the vulnerability, was not subject to any export restrictions. Its newer sibling Mythos 5 was treated differently, however: US authorities temporarily blocked it precisely because of concerns about how well it performed at finding vulnerabilities in other systems. Nor does this apply only to closed models. The nonprofit organization SaferAI recently found that the freely available GLM-5.2 model from the Chinese company Z.ai trails OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 by only a few months.
Sources: techcrunch.com, theguardian.com and forbes.com



