Signum
Feed
Useful signal18 Sept 2026high confidence

Security researchers used Anthropic's Claude Opus 5 to chain two vulnerabilities and breach OpenAI employee accounts via a bug-bounty exercise

A three-person security team (Hacktron AI) used Anthropic's Claude Opus 5 to chain two vulnerabilities (a memory bug in libheif triggered via Discourse's image-upload pipeline, plus a second flaw) to compromise OpenAI employee ChatGPT/Codex accounts, including one with GitHub org access, as part of OpenAI's bug bounty program. The exploit was found July 25, reported to OpenAI, fixed by Discourse July 27, and OpenAI paid Hacktron a $6,500 bounty. OpenAI says the issues are resolved.

CapabilityInfrastructureGovernance

Entities: Anthropic, OpenAI, Hacktron AI, Claude Opus 5, Claude Opus 4.8, Discourse

72Useful signal
1 source
0 primary
Was this useful?
01

What happened

A three-person team (Hacktron AI) used Anthropic's Claude Opus 5 to chain two software flaws, a memory bug in libheif reached through Discourse's image-upload pipeline, plus a second vulnerability, to break into OpenAI employee ChatGPT/Codex accounts, including one with GitHub org access. This ran through OpenAI's official bug bounty program: found 25 July, reported, fixed by Discourse 27 July, and paid a $6,500 bounty. OpenAI says the issue is resolved. The notable detail is a stated capability gap: the same team reportedly failed with Claude Opus 4.8 across several sessions but succeeded with Opus 5 within hours on the same target.

02

Why it matters

This is a real exploit against a live target, not a lab demo, and it went through a bounty program precisely because that kind of live-fire test is how large companies are supposed to find these holes. For security teams, the practical takeaway is narrower than the framing suggests: check exposure in image-upload pipelines using ImageMagick/libheif, since that is the concrete, fixable lesson here. The broader claim, that this shows frontier models meaningfully lower the barrier to cyberattacks for smaller actors or states, rests on a single before/after anecdote from the vendor doing the hacking and is not independently verified.

03

What is noise

The nation-state extrapolation comes from an anonymous commentator, not from any evidence in the reporting, and should be read as speculation. The Opus 4.8-to-Opus 5 capability jump is a self-reported claim from the same team that benefits commercially from appearing to have a cutting-edge AI hacking tool, with no third-party replication cited. The extraction also pulled in unrelated entities (Z.ai, GLM-5.2, SaferAI, Mythos 5), a sign this event may be bundled from a newsletter roundup rather than a single clean incident, and no primary evidence links were captured, which weakens direct verification of the specifics.

04

Watch next

  1. 01Whether Hacktron AI or another researcher publishes a reproducible technical writeup or CVE for the libheif/Discourse chain, allowing independent verification of the exploit and the Opus 4.8 vs Opus 5 capability claim.
  2. 02Whether other security firms or red teams report similar before/after results with Claude Opus 5 versus earlier models on unrelated targets, which would test whether this is a genuine capability jump or a one-off.
  3. 03Whether OpenAI, Discourse, or other companies using ImageMagick/libheif in upload pipelines issue patches or advisories beyond the July 27 fix, and whether a CVE is eventually assigned.

Coverage

1 story

More capability signals

Full feed →