Hacktron Used Claude to Break Into OpenAI in 72 Hours
The attack chain is real, documented, and merged into OpenAI's own monorepo. Every operator running LLM agents near production code now has a concrete case study for their threat model — and the threat is the tooling itself.

On July 25, a team of security researchers at Hacktron AI opened pull request #1186742 in OpenAI's internal monorepo. They did not work at OpenAI. They had not found an inside source. They spent 72 hours chaining two vulnerabilities, used an AI model to write a working exploit, hijacked an OpenAI employee's account, and then politely stopped.
The consensus response: OpenAI's bug bounty program worked. Researchers found a bug, reported it responsibly, got paid $6,500, and the patch landed within a weekend. Everyone move on.
That reading is accurate and almost completely beside the point.
What Actually Happened
(cite index="19-16">The Hacktron team obtained remote code execution and administrative access to the Discourse environment hosted at community.openai.com — OpenAI's public help forum. The entry point was an image upload vulnerability. (cite index="28-4,28-5,28-6,28-7,28-8">On July 24, the researchers used Claude Opus 4.8 to develop a working ImageMagick/libheif code-execution exploit. When Anthropic released Claude Opus 5.5 that evening, they started a new session, which produced a working ARM64 exploit for a local Mac within three hours. They asked it to port the exploit to the x86-64 environment and jemalloc configuration used by Discourse. By 6:00 a.m. on July 25, they had confirmed local RCE through an image upload.
That is not a theoretical capability. That is a frontier model being used as an exploit-development engine, overnight, by researchers who knew what they wanted.
From RCE on the forum, the path was short. (cite index="2-5,2-6">Any user or OpenAI employee logging into the help forum could have had their ChatGPT and Codex accounts taken over, with access to GitHub, Slack, and emails.
(cite index="28-11,28-12">The researchers took over an OpenAI employee's account whose Codex was connected to OpenAI's GitHub organization. They sent a prompt to this employee's Codex account to open a PR in the internal monorepo.
Translation: they did not write a single line of exploit code against GitHub. They borrowed an employee's already-trusted agent and told it to knock.

The Part the Patch Does Not Fix
(cite index="19-10">The entire timeline from initial discovery to OpenAI repo access took less than 72 hours. That number is the tell. This was not a months-long nation-state campaign. It was: identify attack surface, use a frontier model to compress the hard part, chain the output into a live credential, demonstrate impact.
A separate finding from BeyondTrust's Phantom Labs shows the same structural problem. (cite index="11-1,11-2,11-3">A vulnerability in how Codex processes branch names allowed manipulation of the branch parameter to inject arbitrary shell commands. Tasks run inside managed container environments with short-lived GitHub OAuth tokens, creating a sensitive execution layer. (cite index="11-6,11-7">An attacker with repository access could embed malicious payloads in GitHub branch names to compromise multiple users interacting with the same project. (cite index="12-2,12-3">BeyondTrust reported this vulnerability via Bugcrowd in December 2025, with initial fixes within a week and full remediation in January 2026.
Two research teams. Two attack paths. Both reaching into OpenAI's production infrastructure through the seam between AI agents and the credentials those agents carry.
The problem is not vulnerable software. Every organization ships vulnerable software. The problem is attack geometry. (cite index="4-4">"Most enterprises have not yet applied the same least-privilege and behavioral monitoring disciplines to AI tools that they apply to human identities, and that asymmetry is what attackers are now actively exploiting."
The attacker did not need deep OpenAI knowledge. They needed a public forum, a known image processing bug, a frontier model to write the exploit, and the assumption that someone inside had Codex connected to GitHub without tight scope controls. All of those conditions exist at a large number of engineering organizations that are not OpenAI.
If your CI/CD pipeline has an LLM agent that can open pull requests and authenticates with a token that does not expire, you have the threat surface the Hacktron team walked through. The fact that they stopped at PR #1186742 is a choice they made.
(cite index="10-11">The combination of AI and OAuth tokens will present attackers with a widening attack surface at least through 2026.
What to watch: Whether GitHub, GitLab, and Atlassian ship mandatory scope restrictions and audit logs for AI agent tokens in the next two quarters. Whether the first enterprise insurance claim cites LLM-assisted exploitation as the attack vector, triggering a rewrite of AI governance clauses. And whether OpenAI's bug bounty program updates its scope to address AI-agent privilege chains.
- Hacking OpenAI | Hacktron AI
- Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise
- Command Injection Bug in OpenAI Codex Exposed GitHub OAuth Tokens
- Attack Targeting OpenAI Codex Users Exposes AI Software Supply Chain Risks
- Bug Hunters Used Claude to Hack OpenAI
- AI Developer Supply Chain: OpenAI Codex Token Theft – Lab Space
- Bug Bounty: OpenAI - Bugcrowd
- Bug Bounty: Safety Bug Bounty - Bugcrowd
- Announcing OpenAI’s Bug Bounty Program | OpenAI
- RegreSSHion
- Black Hat 2026: If You Run These Automations, You’re Exposed Too: Critical Flaws in Anthropic, Google, and OpenAI’s Coding Agents | Novee
- OpenAI patches twin leaks as Codex slips and ChatGPT spills | CSO Online
- OpenAI fixes Codex flaw that could lead to GitHub token theft | news | SC Media
- Command Injection Bug in OpenAI Codex Exposed GitHub OAuth Tokens - Decipher
- OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens
- Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise - SecurityIT | Cyber Security Consulting
- OpenAI Codex (AI agent)
- OpenAI Codex Vulnerability Allowed Theft of Developers' GitHub Tokens - HackYourMom
- not just development tools security experts discover critical flaw in openais codex which could compromise entire enterprise organizations
- Blog | Hacktron AI
- Pwning OpenAI Atlas Through Exposed Browser Internals | Hacktron AI
- The OpenAI-Hugging Face ExploitGym Incident: A Complete Technical Timeline
- Here’s How an OpenAI Model Went Rogue and Hacked Hugging Face | Hacktron AI
- Hacktron AI (@HacktronAI) / Posts / X
- AI Code Review & Security Vulnerability Detection | Hacktron AI
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- Hacktron AI · GitHub
- Breaking Into PostHog Prod Database | Hacktron AI
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
- I Let Claude Opus Write a Chrome Exploit: The Next Model (Mythos?) Won't Need My Help? | Hacktron AI
- Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies | OALABS Research
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
- Hackers Use ChatGPT and Claude to Build Cyberattacks [2026]