Research · curated 18 Sep 2026

Hacking OpenAI

Coverage timeline

discovered hacktron.ai primary 18 Sep 2026theregister.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

The Hacktron research shows frontier LLMs like Claude Opus 5 can autonomously generate working RCE exploits and chain vulnerabilities into full account takeover, lowering the barrier for AI-assisted offensive operations against even AI vendors themselves.

Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini used Anthropic's Claude Opus models to discover and weaponize a heap buffer overflow in the libheif library, achieving RCE on OpenAI's Discourse-based community forum (community.openai.com) and chaining it with an SSO identity flaw to take over multiple OpenAI employees' ChatGPT and Codex accounts. They demonstrated access to an internal OpenAI monorepo via a harmless pull request, all within 72 hours, earning a $6,500 bug bounty; OpenAI and Discourse have since patched the issues.