How a Hacker Used Anthropic's Claude to Breach OpenAI
Hacktron AI spent under $3,000 in Claude API credits to develop an exploit that cascaded from a Discourse forum into OpenAI's internal GitHub monorepo — exposing a new class of attack where competitor models become the weapon.
The AI Is the Weapon Now
A research team called Hacktron AI spent less than $3,000 in Anthropic API credits to breach OpenAI. That is the headline number. The far more unsettling detail is how they did it: they asked Claude — Anthropic’s own model — to help them write the exploit, and Claude obliged.
The attack is a textbook example of a new attack vector that the AI industry has barely begun to discuss. It is not a prompt injection. It is not a data poisoning attempt. It is something simpler and more durable: using a competitor’s public AI API as a competent, tireless research assistant to find and exploit vulnerabilities in your infrastructure.
The Chain, Step by Step
Hacktron AI began with Discourse, the open-source forum software that powers the OpenAI Developer Community. Discourse relies on a library called FastImage for image validation, and FastImage does not support the HEIF format. So Discourse falls back to ImageMagick’s magick command to handle those files — a dependency that, as Hacktron AI reported, exposes the underlying parser to attacker-controlled content.
The researcher asked Claude Opus 4.8 to audit the installed libheif package for security issues. Claude identified that certain security patches had not been backported. That gap created a heap buffer overflow, allowing out-of-bounds reads and writes during HEIC image decoding — a classic recipe for remote code execution.
From there, Hacktron AI used Claude Opus 4.8 to develop an exploit targeting x86-64 environments with ASLR disabled. When that reached a dead end, they pivoted to the newly released Claude Opus 5, asking it to port the exploit to the specific Discourse configuration running at OpenAI. Claude complied. The result was a working image-upload exploit that achieved local remote code execution.
From Forum to Monorepo
With RCE on the Discourse instance, the next target was identity. The forum uses OpenAI’s single sign-on. Compromising the forum meant compromising any user account linked through that SSO — including employee accounts connected to Codex, OpenAI’s AI coding assistant, and by extension, the company’s internal GitHub repository.
Hacktron AI hijacked a Codex account belonging to an OpenAI employee. That account had access to OpenAI’s internal monorepo. The researchers confirmed the breach by leaving a message inside the repository and then stopped. No data exfiltration. No sabotage. Just proof of access, delivered through the very system they were supposed to protect.
They reported the vulnerability through OpenAI’s bug bounty program and received a $6,500 payout. OpenAI acknowledged the report publicly. The flaw has since been patched.
What This Means for the Industry
The most important quote from Hacktron AI is not about Discourse at all. It is this: the vulnerability is not Discourse-specific. It is an SSO problem. Any first-party or third-party service using OpenAI’s authentication can be entered through the same door. Discourse was merely the entry point they chose to demonstrate the chain.
This matters because the attack cost $3,000 in Claude API tokens and required no zero-day on Anthropic’s side, no insider threat, and no physical access. The tool used to breach OpenAI was a product sold by its competitor — and Claude did not refuse to help.
We are entering an era where every public AI API is a potential force multiplier for adversaries. A well-funded researcher can now rent a world-class reasoning engine by the token and apply it to finding weaknesses in any system that integrates with that API’s ecosystem. The barrier to entry has collapsed from “requires deep expertise in exploit development” to “has a credit card and a prompt.”
Who Wins, Who Loses
OpenAI loses credibility here, even though the actual financial and operational damage was minimal. The image is what matters: a competitor’s AI helped someone walk into their internal codebase. That image will outlast the patch.
Anthropic gains nothing directly from this — no credit, no exposure they asked for — but the incident quietly proves that Claude is effective at exactly the kind of technical reasoning that makes it valuable to attackers as well as defenders. Every company integrating Anthropic’s API into their products should now ask whether that integration creates an indirect attack surface.
Hacktron AI wins the bug bounty and a demonstration that will reshape how security teams think about AI-assisted penetration testing. Their methodology — use the target’s own ecosystem tools against them — is replicable.
What Happens Next
Expect this pattern to multiply. Other companies with SSO-linked services, public APIs, and open-source dependencies will find themselves on the receiving end of the same playbook. The $3,000 spend is a floor, not a ceiling. As models improve and pricing drops, the cost of mounting this kind of attack will approach zero.
Security teams will need to treat competitor AI APIs as a class of tool that attackers will legitimately use — the same way they already treat public code search, automated vulnerability scanners, and cloud cost estimators. The defense is not to block AI access. It is to harden the boundaries between public-facing services and internal systems, enforce strict SSO segmentation, and assume that any vulnerability discoverable by a well-prompted model is discoverable by an adversary who has already done the prompting.
OpenAI’s bug bounty program did its job — it turned a breach into a paid fix. But the real lesson is that the fix is necessary and insufficient. The attack vector it revealed is not going away.