Security researchers used Anthropic's Claude Opus 5 to chain two vulnerabilities and breach OpenAI employee accounts via a bug-bounty exercise
A three-person security team (Hacktron AI) used Anthropic's Claude Opus 5 to chain two vulnerabilities (a memory bug in libheif triggered via Discourse's image-upload pipeline, plus a second flaw) to compromise OpenAI employee ChatGPT/Codex accounts, including one with GitHub org access, as part of OpenAI's bug bounty program. The exploit was found July 25, reported to OpenAI, fixed by Discourse July 27, and OpenAI paid Hacktron a $6,500 bounty. OpenAI says the issues are resolved.
Entities: Anthropic, OpenAI, Hacktron AI, Claude Opus 5, Claude Opus 4.8, Discourse
0 primary
What happened
A three-person team (Hacktron AI) used Anthropic's Claude Opus 5 to chain two software flaws, a memory bug in libheif reached through Discourse's image-upload pipeline, plus a second vulnerability, to break into OpenAI employee ChatGPT/Codex accounts, including one with GitHub org access. This ran through OpenAI's official bug bounty program: found 25 July, reported, fixed by Discourse 27 July, and paid a $6,500 bounty. OpenAI says the issue is resolved. The notable detail is a stated capability gap: the same team reportedly failed with Claude Opus 4.8 across several sessions but succeeded with Opus 5 within hours on the same target.
Why it matters
This is a real exploit against a live target, not a lab demo, and it went through a bounty program precisely because that kind of live-fire test is how large companies are supposed to find these holes. For security teams, the practical takeaway is narrower than the framing suggests: check exposure in image-upload pipelines using ImageMagick/libheif, since that is the concrete, fixable lesson here. The broader claim, that this shows frontier models meaningfully lower the barrier to cyberattacks for smaller actors or states, rests on a single before/after anecdote from the vendor doing the hacking and is not independently verified.
What is noise
The nation-state extrapolation comes from an anonymous commentator, not from any evidence in the reporting, and should be read as speculation. The Opus 4.8-to-Opus 5 capability jump is a self-reported claim from the same team that benefits commercially from appearing to have a cutting-edge AI hacking tool, with no third-party replication cited. The extraction also pulled in unrelated entities (Z.ai, GLM-5.2, SaferAI, Mythos 5), a sign this event may be bundled from a newsletter roundup rather than a single clean incident, and no primary evidence links were captured, which weakens direct verification of the specifics.
Watch next
- 01Whether Hacktron AI or another researcher publishes a reproducible technical writeup or CVE for the libheif/Discourse chain, allowing independent verification of the exploit and the Opus 4.8 vs Opus 5 capability claim.
- 02Whether other security firms or red teams report similar before/after results with Claude Opus 5 versus earlier models on unrelated targets, which would test whether this is a genuine capability jump or a one-off.
- 03Whether OpenAI, Discourse, or other companies using ImageMagick/libheif in upload pipelines issue patches or advisories beyond the July 27 fix, and whether a CVE is eventually assigned.
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- AI systems outperform expert humans in persuasive communication22 Jun 202681
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680