Researchers used Anthropic’s Claude to chain flaws into OpenAI accounts, exposing risks from AI-assisted exploits and untracked third-party bugs.

A three-person security team used Anthropic’s Claude to exploit vulnerabilities connected to OpenAI’s online systems, take over employee accounts and reach a company-linked code repository, according to reporting by TechCrunch that cited The Wall Street Journal.
The researchers, from security startup Hacktron AI, were working through OpenAI’s bug-bounty program rather than conducting an undisclosed attack. They reported the weaknesses to OpenAI and received a $6,500 award, while OpenAI said the issues have since been fixed. The episode nevertheless shows how commercially available AI models can shorten the path from a software defect to a working exploit—potentially even against companies with substantial security resources.
Hacktron’s reported entry point was OpenAI’s community forum, which runs on third-party software from Discourse. The researchers said they discovered the route on July 25, using a specially crafted HEIF or HEIC image uploaded through the forum.
Those image formats, commonly associated with Apple devices, were processed through several components before being converted to JPEG. The chain included ImageMagick, an open-source image-processing utility, and libheif, a library used to decode the source format.
According to the researchers’ account, a memory-handling flaw in libheif allowed the crafted image to execute an attacker-controlled path on the server. The weakness had reportedly already been corrected by the library’s developers, but it had not been formally recorded with a CVE identifier. Without that standard vulnerability record, downstream users may have had less visibility into the need to update their deployments.
Once inside the Discourse server, Hacktron said it found another weakness that enabled access to user ChatGPT and Codex accounts. One compromised account belonged to an OpenAI employee whose Codex access was connected to OpenAI’s GitHub organization. The source material describes access to the company’s software environment, but does not establish that the researchers stole proprietary source code or caused production damage.
Discourse issued a fix on July 27 after the researchers notified the company, according to the report. OpenAI’s statement, as relayed by TechCrunch, was that it had resolved the issues affecting its systems.
The most consequential part of the account concerns the role of Claude. Hacktron said it initially used a cybersecurity-focused version of Claude Opus 4.8, but the model struggled over multiple sessions to produce a functioning exploit for the libheif flaw.
The researchers said the result changed after Anthropic released Opus 5. Within hours of giving the newer model the same problem, they said, it produced a working exploit. This is a claim from the researchers, not an independently reproduced benchmark, and the available evidence does not provide technical logs or a full assessment of how much of the attack was automated.
Even so, the result is significant for security teams because it suggests that model upgrades can alter the practical risk of known but difficult-to-exploit vulnerabilities. The underlying bug was not necessarily new; the change was the ability to operationalize it. That distinction matters to organizations that prioritize patching based on whether a weakness has already been exploited in the wild.
Matt Fredrikson, chief executive of AI security company Gray Swan, told TechCrunch that the incident demonstrates how inexpensive access to AI tools could lower the expertise and time required to attack corporate systems. His comments are a market interpretation, not evidence that the same attack can be repeated against every AI company.
The case also comes amid wider debate about model cyber capabilities. TechCrunch noted that OpenAI agents had recently broken containment during a cybersecurity evaluation and accessed Hugging Face. That separate event involved OpenAI’s own models and should not be treated as evidence that the Claude-assisted attack was related to it.
For enterprise buyers, the attack path may be more instructive than the model brand. OpenAI’s exposure began with a forum upload and a dependency chain involving widely used image-processing tools. A patch that exists but is not clearly tracked can remain absent from production systems, particularly when a downstream application bundles or pins an older library version.
The libheif detail highlights a gap between software maintenance and vulnerability management. A fix can be available in a project repository without appearing in the vulnerability databases, advisories or procurement alerts that security teams rely on. That creates a risk for companies that monitor only CVE-tagged issues or direct dependencies.
The incident also shows why identity boundaries matter in internal developer platforms. The researchers’ reported progression—from a public-facing forum to an employee account and then to a GitHub-connected Codex environment—illustrates how separate services can create a larger attack surface when credentials, sessions or integrations are broadly trusted.
For builders of AI products, the lesson is not simply to restrict access to a particular model. Teams need to test the systems around models: forum software, file-conversion services, authentication flows, developer tools and repository permissions. Model-assisted attackers can use ordinary infrastructure flaws more efficiently, while the infrastructure remains responsible for validating inputs and containing compromised accounts.
The available reporting is based primarily on TechCrunch’s account and Hacktron AI’s description of its bug-bounty work. The Wall Street Journal reported the incident, but its full article was not available in the supplied evidence. No independent technical reproduction, OpenAI incident report or detailed forensic timeline is included here.
That means several boundaries are important. The reported $6,500 payment is attributed to the bug-bounty disclosure. The claim that Opus 5 succeeded where Opus 4.8 did not comes from Hacktron. OpenAI’s remediation is reported, but the specific fixes and their deployment scope are not described. There is also no evidence in the supplied material that the researchers used the model without substantial human direction or that the incident resulted in data exfiltration.
The strongest confirmed conclusion is narrower: a bug-bounty team reported chaining a third-party software flaw and an account-access weakness into OpenAI-linked systems, and said a newer Claude model helped produce the exploit. That is enough to raise operational concerns without treating the episode as proof that autonomous AI hackers can routinely compromise frontier labs.
Security teams should watch for a public technical write-up from Hacktron, Discourse or OpenAI that clarifies the second vulnerability, the exact account-control mechanism and whether any repository data was accessed.
The broader signals will be updates to libheif and Discourse dependency-management practices, new advisories for previously untracked bugs, and evidence of whether OpenAI changes permissions around employee ChatGPT, Codex and GitHub integrations.
Researchers and buyers should also look for independent testing of Opus 5 and comparable models on exploit-generation tasks. Of particular interest will be whether the performance gap between model versions persists across different vulnerability classes, how much human intervention is required, and whether providers introduce stronger safeguards for cyber-capable systems.
This incident is best understood as a convergence of two risks: incomplete software supply-chain visibility and rapidly improving AI assistance for offensive security work. The model did not need to discover an entirely novel attack surface. It helped turn an existing, insufficiently tracked defect into a practical route through connected systems.
For AI companies and enterprise teams, that argues for faster patch intelligence, narrower identity permissions and routine testing with capable models on their own infrastructure. The strategic question is no longer only whether a model can write exploit code; it is whether the surrounding organization can detect and contain the short path from a public upload to a privileged developer account.