Claude Opus 5 Just Bought OpenAI Staff Accounts for $6,500
Three researchers at Hacktron used Anthropic's latest model to chain a forum bug into a staff account takeover at OpenAI. The $6,500 bounty is a fraction of what this could have cost — and the methodology just got cheaper.
The Cheapness of It All
OpenAI paid Hacktron $6,500. The AI tooling cost was under $3,000 across the broader campaign. The researchers spent roughly two months chaining exploits. By every measure that matters to a defense team, this was a bargain.
The attack itself is a story about how far a capable model can carry a skilled human — and how little friction now separates a vulnerability in a public help forum from a foothold inside a lab’s code repositories.
Three researchers at Hacktron, describing itself as an AI-assisted security research firm, started with a bug in Discourse, the open-source software behind OpenAI’s public forums. They moved through a weakness in OpenAI’s own login infrastructure. Within 72 hours they had taken over ChatGPT and Codex accounts belonging to employees. One internal pull request proved the access. No source code was read. No customer data was touched. The chain stopped there, by design.
OpenAI confirmed a fix about 14 hours after the report and issued the bounty payment on September 1. The company has not publicly described the login flaw, choosing instead to signal through action rather than disclosure.
What makes this case worth studying goes beyond any single bug. It is the rate at which capable AI models are compressing the time and expertise required to build working exploit chains against real targets.
How a Forum Became a Backdoor
The entry point was an image-processing flaw. Discourse passes uploaded HEIC and HEIF images through ImageMagick, which relies on the libheif library. A vulnerability in libheif — tracked as CVE-2026-32882 — allowed a specially crafted image to corrupt the forum server’s memory.
The upstream fix landed in libheif 1.22.0 in May 2026. But the Discourse server image running on Debian 12 at the time of the test in July still shipped version 1.19.7. The vulnerability was public. The patch existed. The deployment had not caught up.
That gap between a published fix and its presence on a running server is one of the most common failure modes in infrastructure security. What is notable here is what the researchers did with the foothold.
From the forum server, they leveraged OpenAI’s single sign-on system. The forum offered a Sign in with OpenAI option — the same authentication flow staff used across internal tools. Once the researchers controlled the forum, they could hijack the sessions of any OpenAI employee who had authenticated through it. No additional social engineering. No phishing. The victims took no action.
Hacktron characterized this as an OpenAI identity problem, not a Discourse problem. Any service using the same SSO token could have granted equivalent access. The same pattern would apply to Slack, GitHub, or email if those tools shared the identity provider — and the researchers said the chain could, in theory, reach all of them.
That wider reach was possible. It was not used. The boundary the researchers drew is telling: they proved the internal access, triggered one pull request, and stopped.
The Model That Closed the Gap
The exploit chain required defeating ASLR, a standard memory protection. Hacktron first tried Claude Opus 4.8, which struggled across multiple sessions to produce a working payload once ASLR was active.
Anthropic released Claude Opus 5 on the evening of July 24. In a fresh session, the model produced a working exploit within hours.
Opus 5 shipped with safeguards designed to prevent the model from writing exploit code targeting real systems. The researchers worked around these by directing the model at their own test server, disguised as a capture-the-flag practice target, and running it in an automated loop. They stress this was not hands-off hacking. Skilled human direction remained essential throughout.
The result fits a pattern Anthropic and other labs have documented this year: frontier models are sharply reducing the skill floor for serious offensive work. Anthropic has reported that criminal and state-backed actors are already using Claude models to conduct real intrusions. OpenAI is now a named target in that dynamic.
Beyond OpenAI
Hacktron called the broader effort HEIF Heist. Over roughly two months, the team identified the same class of image-decoding flaw in software used by other large companies. The total AI cost remained under $3,000.
The campaign links to reported bugs in Slack, Meta’s products, GitHub Enterprise, and Next.js. Vercel’s advisory confirms the Next.js flaw. Libheif maintainers confirmed a working code-execution exploit tied to Meta. Claims of code execution across the full set of affected applications remain unevenly supported. The Hacker News noted this limitation when covering the Next.js flaw in August.
One detail stands out: for targets where the team had no prior knowledge, they switched from Claude Opus 5 to OpenAI’s own GPT-5.6 Sol. The model choice followed the information available, not brand loyalty. Only Shopify appears to have noticed the activity, despite repeated crashes under test uploads.
What This Means for AI Lab Security
The immediate implication is operational. Any organization running a Discourse server should rebuild on the latest image. A web-interface update alone will not replace the old library. Patched self-hosted releases are 2026.7.0, 2026.6.1, 2026.5.2, and 2026.1.6. Organizations should update libheif to 1.23.4 or their distribution’s patched build.
The structural implication is deeper. Single sign-on is a force multiplier for convenience and a force multiplier for risk. When a public-facing service and an internal tool share the same identity provider, a compromise at the edge becomes a compromise at the core. The OpenAI case is a textbook example of that amplification.
There is no indication the OpenAI flaw was exploited against anyone outside the research scope. As of mid-September 2026, it did not appear on the U.S. government’s list of vulnerabilities known to be actively exploited — though absence from that list is not evidence of safety.
The broader question is whether organizations that have already patched should audit for prior access. On that point, the available sources are silent. The researchers’ discipline in limiting the chain suggests good faith, but good faith is not a security guarantee.
The Real Cost
Six thousand five hundred dollars is a modest bounty. Three thousand dollars in AI compute is negligible. Two months of research from a small team is a tight timeline.
What the attackers demonstrated is repeatable. The same class of flaw exists in libheif deployments across the internet. The same SSO patterns connect public services to internal infrastructure at companies of every size. The model capability that closed the ASLR gap in hours is now a shipped product, not a research prototype.
The race between labs is often framed in terms of model capability. This incident reframes it. Claude Opus 5 did not just write better text. It helped a three-person team turn a forum bug into a staff account takeover faster than the target could patch it. The defensive side still responded in 14 hours. But the offensive side no longer needs a nation-state budget to make that kind of chain work.
The $6,500 check is not the story. The story is that the barrier to producing it just dropped below what most security teams can afford to ignore.