Skip to content

Hacktron AI Claims Three-Person Team Breaches OpenAI Codebase in Under 72 Hours Using Claude-Assisted Attack

Sep 21, 2026
The Rundown AI
Article image for Hacktron AI Claims Three-Person Team Breaches OpenAI Codebase in Under 72 Hours Using Claude-Assisted Attack

Summary

Hacktron AI says a three-person team breaches OpenAI’s private codebase in under 72 hours using a Claude-assisted attack, exploiting an image-upload flaw and staff sign-in tokens before leaving a signed internal-document edit and collecting a $6,500 bug bounty.

Key Points

  • Hacktron AI says its three-person team breaches OpenAI’s private codebase in under 72 hours, taking over employee accounts with an attack partly written by Anthropic’s Claude.
  • The researchers exploit an image-upload flaw in OpenAI’s community forum, then use a second vulnerability to turn staff sign-in tokens into access to ChatGPT accounts.
  • Hacktron leaves a signed edit in an internal OpenAI documentation file as proof, reports the flaws, and receives a $6,500 bug bounty.

Tags

Read Original Article