Three-person research team used Claude and Codex to breach OpenAI's Discourse forum instance and access employee GitHub accounts
Independent security researchers at Hacktron used Claude Opus 4.8/5 (and Codex) to find and exploit a HEIF image-processing vulnerability in Discourse (the third-party forum host used by OpenAI), achieving remote code execution on Discourse Cloud and gaining access to OpenAI's Discourse instance and an employee's Codex/GitHub account. They sent a pull request from a compromised employee account to a private OpenAI repo ('Monorepo') as proof of access but did not access the internal code itself. The same exploit ('HEIF Heist') was adapted within 1-2 days to also target Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others, for under $3,000 in AI token costs. The vulnerability has since been patched; OpenAI paid Hacktron a $6,500 bug bounty.
Entities: OpenAI, Anthropic, Claude Opus 5, Claude Opus 4.8, Codex, Hacktron
0 primary
What happened
A three-person team at Hacktron used consumer Claude and Codex subscriptions to find and exploit a HEIF image-processing vulnerability in Discourse, the third-party forum software OpenAI uses. This gave them remote code execution on Discourse Cloud, access to OpenAI's forum instance, and access to an employee's Codex/GitHub account, which they used to send a proof-of-access pull request to a private OpenAI repo without reading the actual code. Within one to two days they adapted the same exploit to hit Slack, Meta, GitHub Enterprise, Rails, Next.js and ImageMagick, for under $3,000 in AI token costs. The bug is now patched and OpenAI paid a $6,500 bounty.
Why it matters
This is a concrete data point on the cost and speed of AI-assisted offensive security: a small team without special access broke into infrastructure touching several major tech companies for the price of a laptop and a few subscriptions. Security and engineering leaders at any company using Discourse, or similarly common third-party software, should treat this as a live reminder that shared infrastructure is a single point of failure across many unrelated organisations. The detail that only one of the affected companies (Shopify) noticed the intrusion is arguably more important than the exploit itself, since it points to a detection gap rather than just an exploitation gap.
What is noise
The framing that this "breached OpenAI" oversells it: the researchers reached a forum instance and one employee's GitHub account, not OpenAI's core systems or model weights, and explicitly did not access the private repo's code. This is second-hand reporting (The Verge summarising a Wall Street Journal piece) with no linked technical writeup, advisory or CVE, so specifics like the exact cost breakdown and the "only Shopify detected it" claim cannot be independently verified here. Any suggestion that internal secrets or code were exposed is unsupported speculation, not a confirmed outcome.
Watch next
- 01Whether Hacktron or Discourse publishes a technical writeup or CVE with reproducible details of the HEIF vulnerability and the exploit chain
- 02Whether any of the other named targets (Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick) confirm they were affected and disclose their own detection or lack of it
- 03Whether bug bounty payouts or disclosure timelines for AI-assisted exploit discoveries start trending faster or cheaper across the industry over the next two to three quarters
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- AI systems outperform expert humans in persuasive communication22 Jun 202681
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680