◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL
THE DIGITAL ALCHEMIST
SecurityIMPACT 91

Hacktron Used Claude to Break Into OpenAI in 72 Hours

The attack chain is real, documented, and merged into OpenAI's own monorepo. Every operator running LLM agents near production code now has a concrete case study for their threat model — and the threat is the tooling itself.

2026-09-184 MIN READ#OpenAI · #Codex · #Bug Bounty · #LLM Security · #GitHub · #Red Team · #AI Agents · #CI/CD
The Digital Alchemist
The Digital Alchemist

On July 25, a team of security researchers at Hacktron AI opened pull request #1186742 in OpenAI's internal monorepo. They did not work at OpenAI. They had not found an inside source. They spent 72 hours chaining two vulnerabilities, used an AI model to write a working exploit, hijacked an OpenAI employee's account, and then politely stopped.

The consensus response: OpenAI's bug bounty program worked. Researchers found a bug, reported it responsibly, got paid $6,500, and the patch landed within a weekend. Everyone move on.

That reading is accurate and almost completely beside the point.

What Actually Happened

(cite index="19-16">The Hacktron team obtained remote code execution and administrative access to the Discourse environment hosted at community.openai.com — OpenAI's public help forum. The entry point was an image upload vulnerability. (cite index="28-4,28-5,28-6,28-7,28-8">On July 24, the researchers used Claude Opus 4.8 to develop a working ImageMagick/libheif code-execution exploit. When Anthropic released Claude Opus 5.5 that evening, they started a new session, which produced a working ARM64 exploit for a local Mac within three hours. They asked it to port the exploit to the x86-64 environment and jemalloc configuration used by Discourse. By 6:00 a.m. on July 25, they had confirmed local RCE through an image upload.

That is not a theoretical capability. That is a frontier model being used as an exploit-development engine, overnight, by researchers who knew what they wanted.

From RCE on the forum, the path was short. (cite index="2-5,2-6">Any user or OpenAI employee logging into the help forum could have had their ChatGPT and Codex accounts taken over, with access to GitHub, Slack, and emails.

(cite index="28-11,28-12">The researchers took over an OpenAI employee's account whose Codex was connected to OpenAI's GitHub organization. They sent a prompt to this employee's Codex account to open a PR in the internal monorepo.

Translation: they did not write a single line of exploit code against GitHub. They borrowed an employee's already-trusted agent and told it to knock.

The Digital Alchemist
The Digital Alchemist
The OpenAI Breach Chain, By The Numbers
72Hours:discovery tomonorepo PR6,500Bounty paid ($)48Hours:Discourse patchturnaround1BeyondTrustvuln severity(CVSS-equivalent, P1 Critical)
Source: Hacktron AI disclosure report, BeyondTrust Phantom Labs (Dec 2025 / Jul 2026)

The Part the Patch Does Not Fix

(cite index="19-10">The entire timeline from initial discovery to OpenAI repo access took less than 72 hours. That number is the tell. This was not a months-long nation-state campaign. It was: identify attack surface, use a frontier model to compress the hard part, chain the output into a live credential, demonstrate impact.

A separate finding from BeyondTrust's Phantom Labs shows the same structural problem. (cite index="11-1,11-2,11-3">A vulnerability in how Codex processes branch names allowed manipulation of the branch parameter to inject arbitrary shell commands. Tasks run inside managed container environments with short-lived GitHub OAuth tokens, creating a sensitive execution layer. (cite index="11-6,11-7">An attacker with repository access could embed malicious payloads in GitHub branch names to compromise multiple users interacting with the same project. (cite index="12-2,12-3">BeyondTrust reported this vulnerability via Bugcrowd in December 2025, with initial fixes within a week and full remediation in January 2026.

Two research teams. Two attack paths. Both reaching into OpenAI's production infrastructure through the seam between AI agents and the credentials those agents carry.

The problem is not vulnerable software. Every organization ships vulnerable software. The problem is attack geometry. (cite index="4-4">"Most enterprises have not yet applied the same least-privilege and behavioral monitoring disciplines to AI tools that they apply to human identities, and that asymmetry is what attackers are now actively exploiting."

The attacker did not need deep OpenAI knowledge. They needed a public forum, a known image processing bug, a frontier model to write the exploit, and the assumption that someone inside had Codex connected to GitHub without tight scope controls. All of those conditions exist at a large number of engineering organizations that are not OpenAI.

If your CI/CD pipeline has an LLM agent that can open pull requests and authenticates with a token that does not expire, you have the threat surface the Hacktron team walked through. The fact that they stopped at PR #1186742 is a choice they made.

(cite index="10-11">The combination of AI and OAuth tokens will present attackers with a widening attack surface at least through 2026.

What to watch: Whether GitHub, GitLab, and Atlassian ship mandatory scope restrictions and audit logs for AI agent tokens in the next two quarters. Whether the first enterprise insurance claim cites LLM-assisted exploitation as the attack vector, triggering a rewrite of AI governance clauses. And whether OpenAI's bug bounty program updates its scope to address AI-agent privilege chains.

Sources
  1. Hacking OpenAI | Hacktron AI
  2. Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise
  3. Command Injection Bug in OpenAI Codex Exposed GitHub OAuth Tokens
  4. Attack Targeting OpenAI Codex Users Exposes AI Software Supply Chain Risks
  5. Bug Hunters Used Claude to Hack OpenAI
  6. AI Developer Supply Chain: OpenAI Codex Token Theft – Lab Space
  7. Bug Bounty: OpenAI - Bugcrowd
  8. Bug Bounty: Safety Bug Bounty - Bugcrowd
  9. Announcing OpenAI’s Bug Bounty Program | OpenAI
  10. RegreSSHion
  11. Black Hat 2026: If You Run These Automations, You’re Exposed Too: Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents | Novee
  12. OpenAI patches twin leaks as Codex slips and ChatGPT spills | CSO Online
  13. OpenAI fixes Codex flaw that could lead to GitHub token theft | news | SC Media
  14. Command Injection Bug in OpenAI Codex Exposed GitHub OAuth Tokens - Decipher
  15. OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens
  16. Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise - SecurityIT | Cyber Security Consulting
  17. OpenAI Codex (AI agent)
  18. OpenAI Codex Vulnerability Allowed Theft of Developers' GitHub Tokens - HackYourMom
  19. not just development tools security experts discover critical flaw in openais codex which could compromise entire enterprise organizations
  20. Blog | Hacktron AI
  21. Pwning OpenAI Atlas Through Exposed Browser Internals | Hacktron AI
  22. The OpenAI-Hugging Face ExploitGym Incident: A Complete Technical Timeline
  23. Here’s How an OpenAI Model Went Rogue and Hacked Hugging Face | Hacktron AI
  24. Hacktron AI (@HacktronAI) / Posts / X
  25. AI Code Review & Security Vulnerability Detection | Hacktron AI
  26. Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
  27. Hacktron AI · GitHub
  28. Breaking Into PostHog Prod Database | Hacktron AI
  29. Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
  30. I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help? | Hacktron AI
  31. Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies | OALABS Research
  32. Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
  33. Hackers Use ChatGPT and Claude to Build Cyberattacks [2026]
← back to the feed
NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%