In late July 2026, security researchers from Hacktron AI used Anthropic’s Claude artificial intelligence model to exploit a vulnerability chain affecting OpenAI’s ecosystem, successfully compromising employee ChatGPT and Codex accounts within 72 hours. According to reports published by Hacktron AI and confirmed by OpenAI to Agence France-Presse (AFP), the intrusion took place as part of an authorized security exercise designed to identify system vulnerabilities.
The Vulnerability Chain Starting on the OpenAI Community Forum
The attack vector originated on community.openai.com, OpenAI’s community forum powered by Discourse software, as detailed in disclosures by Hacktron AI. Researchers identified a weakness in how the system handled HEIC and HEIF image files through the libheif processing library. By crafting a malicious image file, the team achieved remote code execution on the forum environment and secured administrative access to OpenAI’s Discourse instance.
https://x.com/S1r1u5_/status/2100777801335095383
From that initial foothold, researchers targeted the forum’s single sign-on feature, which permitted logins via OpenAI credentials. By combining the Discourse remote code execution with flaws in the authentication pipeline, the three-person Hacktron AI team gained control over multiple employee ChatGPT and Codex accounts.
According to Hacktron AI, the multi-step attack progression moved from a malicious image to a compromised forum, exploited authentication weaknesses, and ultimately breached employee accounts. Because those accounts maintained authorizations for connected developer and enterprise tools, the team demonstrated potential access to internal repositories, including prompting a Codex instance to create a pull request on an internal GitHub repository without downloading confidential source code.
Role of Anthropic’s Claude in Accelerating the Exploit
The research highlighted the technical capabilities of modern artificial intelligence models in cybersecurity tasks. Hacktron AI initiated their work using Anthropic’s Claude Opus 4.8 model released in May, but reported that the model struggled to locate an entry point within Discourse.

The timeline shifted when Anthropic released the Claude Opus 5 model. According to the researchers, the newer iteration identified and developed a working memory corruption exploit for libheif within three hours. The research team directed the investigations and tested the results, utilizing Claude to compress complex exploit development tasks into a fraction of standard timeframes.
Following the discovery, Hacktron AI notified OpenAI and Discourse. OpenAI deployed patches addressing its systems roughly 14 hours after notification, according to Hacktron AI’s timeline. On September 1, 2026, OpenAI awarded the researchers a 6,500 dollar bug bounty reward for the vulnerability.
Industry Context and Security Implications
The incident arrives amid heightened scrutiny surrounding generative artificial intelligence and software security. In April, Anthropic restricted broad commercial availability of its Mythos model due to cybersecurity risks, limiting access to select organizations for defensive auditing. Anthropic subsequently launched a restricted version named Fable in June, which faced a brief national security suspension by the United States government before receiving clearance two weeks later.
OpenAI acknowledged the findings to AFP, with a company spokesperson stating, “We thank the researchers for having contacted us and having shared their observations.” Hacktron AI confirmed they voluntarily limited their access and did not execute mass data exfiltration of user conversations.
Related reading