BTC$81,057.00▲ 5.99%
ETH$2,630.71▲ 7.33%
USDT$0.9997▲ 0.04%
BNB$763.44▲ 3.99%
XRP$1.40▲ 7.90%
USDC$0.9998▲ 0.02%
SOL$113.38▲ 12.10%
TRX$0.3387▲ 1.11%
ZEC$1,505.72▲ 1.49%
FIGR_HELOC$1.03▲ 2.43%
HYPE$91.72▲ 10.13%
DOGE$0.0882▲ 7.85%
XMR$563.89▲ 9.94%
WBT$83.27▲ 5.63%
BTC$81,057.00▲ 5.99%
ETH$2,630.71▲ 7.33%
USDT$0.9997▲ 0.04%
BNB$763.44▲ 3.99%
XRP$1.40▲ 7.90%
USDC$0.9998▲ 0.02%
SOL$113.38▲ 12.10%
TRX$0.3387▲ 1.11%
ZEC$1,505.72▲ 1.49%
FIGR_HELOC$1.03▲ 2.43%
HYPE$91.72▲ 10.13%
DOGE$0.0882▲ 7.85%
XMR$563.89▲ 9.94%
WBT$83.27▲ 5.63%
Home / AI News / Hacktron AI Used Claude to Breach OpenAI in 72 Hours for $6,500 Bounty
Cybersecurity researcher working at multiple monitors in a dark room, code visible on screens
AI News

Hacktron AI Used Claude to Breach OpenAI in 72 Hours for $6,500 Bounty

CoinPulseHQ Editorial · ·4 min read

Security researchers at Hacktron AI used Anthropic’s Claude Opus 5 large language model to help exploit three separate vulnerabilities and gain access to OpenAI‘s private code repository in under 72 hours, a feat for which OpenAI paid the team a $6,500 bug bounty, according to News.bitcoin. The work took place in late July, with the team reporting the chain through OpenAI’s Bugcrowd program on July 25, 2026, and the vulnerabilities were fixed the same day.

As first reported by the Wall Street Journal on September 17, the Hacktron AI researchers opened a harmless pull request in the openai/openai monorepo to prove they had reached the internal environment, stopping short of examining sensitive source code. Theguardian reported the researchers largely used OpenAI’s own GPT-5.6 Sol model to carry out the hack, despite the initial use of Claude.

Also read: Claude is quietly winning over paying AI consumers, data shows, even as ChatGPT still dominates

Key facts

  • Hacktron AI reported the vulnerability chain through Bugcrowd on July 25, 2026, and collected a $6,500 bounty from OpenAI.
  • Claude Opus 5, released July 24, produced a working ARM64 exploit in hours; Claude Opus 4.8 had failed the same task.
  • The attack chain started with a remote code execution flaw in the ‘libheif’ library inside the Discourse forum software, pivoted through a flaw in OpenAI’s SSO flow, and reached the Codex environment wired to OpenAI’s GitHub organization.
  • Discourse published its advisory on July 28 with a CVSS severity of 8.8.
  • Chainalysis logged 11.1 malicious onchain writes per day, up from 2.06 a year ago, which News.bitcoin tied to the spread of open-weight models released in mid-2025.

How the breach unfolded

The journey began with a vulnerable ‘libheif’ library inside Discourse, the forum software used by OpenAI for staff discussions. That flaw allowed remote code execution on the forum itself. From there, the researchers pivoted through a flaw in OpenAI’s single sign-on flow, took over an employee’s ChatGPT account, and reached the Codex environment connected to OpenAI’s GitHub organization. That path opened the openai/openai monorepo.

Three accounts linked to OpenAI employees, and some unaffiliated users, were impacted. Those ChatGPT and Codex accounts had access to connected services including Outlook, Slack, and GitHub, according to a post on X by AI researcher s1r1us cited by Coinpedia. The team used a pull request as proof of access and then stopped, reporting the issue rather than exploiting it further.

Also read: Claude Opus 4.6 readily bypasses Anthropic's explicit content safeguards, TechCrunch finds

What the AI tools changed

The notable shift was not the presence of vulnerabilities, which are common across software companies, but the speed at which they were converted into working exploits. Memory-corruption exploit development has traditionally taken skilled humans weeks of effort. Here, the entire sequence from initial access to demonstrated control of the repository played out in less than three days.

Hacktron AI told Theguardian that work which once required a well-resourced team and months of effort can now be compressed into days. The startup emphasized that the scope of what it could theoretically access was huge, while stressing that no sensitive code was downloaded.

Why it matters

The economics of exploit development are shifting. A $6,500 bounty was enough to surface a three-stage chain into a major AI lab’s internal repository, which raises questions about whether bug bounty programs can keep pace as AI tools lower the barrier to finding and weaponizing flaws. For crypto, the stakes are directly financial: Chainalysis reported this week that attackers post malware instructions to public blockchains 440% more often than a year ago, using what the firm calls blockchain dead drops, which are command-and-control instructions parked on a ledger that cannot be seized or taken offline. By the second quarter of 2026, state-linked operators from North Korea and Iran accounted for roughly two-thirds of new activity and about half the total, Chainalysis said. Researchers tracking North Korea’s Kimsuky found local LLM platforms including Ollama, GPT4All and Msty installed on the group’s infrastructure alongside AI-generated phishing decoys aimed at virtual asset and financial investment targets. Blockaid counted 212 onchain exploits worth $1.1 billion as AI and wallet attacks accelerated, and Defillama recorded April 2026 as crypto’s most-hacked month on record with 30 incidents.

Coinbase recently warned that bug reports could triple in the near future as AI floods disclosure programs with noise, the awkward corollary of a small bounty surfacing a major breach.

What to watch

Whether OpenAI introduces additional hardening around its SSO flow and connected internal services, and whether other AI labs disclose similar bounty submissions from AI-assisted research teams. Coinbase’s warning about tripling bug reports suggests disclosure programs may need new filtering standards. The long-term question is whether defensive teams can keep pace with AI-accelerated offense, or whether exploit development becomes a commodity service at scale.

CoinPulseHQ Editorial

Written by

CoinPulseHQ Editorial

The CoinPulseHQ Editorial desk covers cryptocurrency, blockchain and AI. Our AI-assisted newsroom builds each article from published, linked sources, checks it for accuracy before it goes live, and our editor reviews published articles and corrects anything that needs it.

Reported by news.bitcoin.com.

Sources: Bitcoin.com News, Theguardian, Coinpedia

CoinPulseHQ Editorial

Editorial desk

The CoinPulseHQ Editorial desk covers cryptocurrency, blockchain and AI. Our AI-assisted newsroom builds each article from published, linked sources, checks it for accuracy before it goes live, and our editor reviews published articles and corrects anything that needs it.