This Is How Three People Hacked OpenAI for the Price of a Subscription
They didn’t write the exploit. Claude Opus 5 did. A poisoned HEIC image, a broken SSO token, and 72 hours later, they were inside OpenAI’s internal code repository.

One HEIC Image, Three Subscriptions, and OpenAI's Internal Repository
On the evening of July 24, 2026, three people at Hacktron AI sat in front of their screens. They had just gotten access to Claude Opus 5. Two days earlier, they had tried the same vulnerability with Opus 4.8 and failed. Now they opened a new session and entered the target: the Discourse forum, HEIC image upload. Three hours later, the first line of ARM64 exploit code appeared in the terminal.
The attack happened inside OpenAI's bug bounty program.
How one image opened a door
OpenAI's community forum runs on Discourse. Discourse lets users sign in with their OpenAI account through single sign-on. The design is convenient, and dangerous. The forum's image upload feature usually checks images with FastImage, but FastImage does not support Apple's HEIC format. So HEIC images are handed to ImageMagick, which then calls libheif for decoding. The installed version of libheif is 1.19.7, which has a heap buffer overflow vulnerability.
The Hacktron team crafted a HEIC image. Upload. Backend parsing. Overflow triggered. Remote code execution access obtained.
The change was who crafted the image. They did not write the exploit code themselves. They handed the task to Opus 5. To bypass the model's guardrail against "writing attack code for real targets," they disguised their test server as a CTF target domain. Opus 5 thought it was playing capture-the-flag and began outputting exploit code.
After the forum was compromised, they found that SSO tokens issued through the forum were also valid on ChatGPT, Codex, and GitHub. Some of those tokens belonged to OpenAI employees. Using an employee's Codex account, they submitted PR #1186742 to the internal code repository. Then they stopped testing and submitted a report.
OpenAI's security team fixed the SSO issue within 14 hours. Discourse later fixed the image parsing vulnerability. OpenAI paid a $6,500 bounty.
From Opus 4.8 to Opus 5: overnight
On July 23, the team had already discovered the vulnerability. They tried to exploit it with Claude Opus 4.8. In a default defensive environment with ASLR enabled, multiple Opus 4.8 sessions could not generate stable exploit code.
On the evening of July 24, Anthropic released Claude Opus 5. The team immediately opened a new session. In the first 3 hours, Opus 5 wrote attack code for the local Mac ARM64 architecture. The team asked it to port the code to the x86-64 environment and jemalloc memory allocator used by Discourse. After one all-nighter, at 6 a.m. on July 25, Opus 5 confirmed the effectiveness of local RCE through image upload. By 10 a.m., the Opus 5 agent, set to an autonomous loop objective, had breached a cloud instance and read low-level system files.
A vulnerability the previous-generation model could not find was deciphered and automatically exploited the day after the new model was released.
In subsequent tests, the team used the GPT-5.6 Sol model. When told only that a vulnerability existed, with no knowledge of the target system, the AI automatically completed memory leaks, privilege escalation, lateral movement, and bypassing existing defenses. That kind of capability used to belong only to nation-state hackers.
The HEIF Heist: only Shopify saw the anomaly
Hacktron named the discovery "The HEIF Heist." libheif is not only in OpenAI's forum. It is widely used to parse HEIC, HEIF, and AVIF images, buried deep in countless applications. The code fix for this vulnerability was actually committed to a branch in the open-source community last year, but no CVE ID was assigned. Downstream operating systems and software did not know about it.
The team used AI as an automated hacker to test internet giants. Slack, Zoom, Meta, and GitHub Enterprise accepted image uploads, and almost all were affected. Ruby on Rails and popular frameworks in the Node.js ecosystem such as Next.js, Astro, and Gatsby called this library, and they could be taken over.
Thousands of test images went out. The image processors of major companies crashed repeatedly. Only Shopify noticed an anomaly. The other companies logged nothing.
The entire "HEIF Heist" project took two months and covered all the giants mentioned above. The total large-model token cost was less than $3,000. For each company, AI needed only one to two days to adapt the "poison image" into a customized attack weapon based on the target environment.
$6,500 and 25% of the engineers
OpenAI paid a $6,500 bounty. For a vulnerability that breached an internal code repository, that number is almost symbolic. After the incident, OpenAI President Greg Brockman said the company had reassigned about 25% of its production engineers to security work.
Discourse fixed the relevant vulnerability on July 25. OpenAI fixed the SSO issue within 14 hours. PR #1186742 was closed.
The software industry has long relied on a barrier: complexity. If a vulnerability in an open-source library is disclosed, even with the source code sitting on the table, an ordinary hacker cannot exploit it. Turning a theoretical memory corruption into a weapon that can break into a server requires rare expertise, a large amount of time, and deep reverse engineering of the target environment. Zero-day weapon development costs are high. Usually only nation-state hacker units will expend that effort for high-value targets. That cost barrier protected ordinary companies.
AI tore down the barrier. It turned once-scarce hacking expertise into cheap compute. Attack work that once required a well-funded team and months of effort is now compressed into days, or even hours.
Hacktron wrote in its report that any three-person team with access to an advanced AI without guardrails can match a nation-state team at security penetration.
Ending
PR #1186742 is still in OpenAI's repository. Status: closed.
There is one anomaly alert in Shopify's logs. There are none in the other companies' logs.
The Opus 5 subscription costs a few dozen dollars. The $6,500 bounty has been paid.
About the Creator
Jin
Writer of reamstories
https://reamstories.com/jin
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.
Comments
There are no comments for this story
Be the first to respond and start the conversation.