LmCast :: Stay tuned in

Security researchers used Claude to help them hack into OpenAI

Recorded: Sept. 18, 2026, 4:10 p.m.

Original Summarized

Security researchers used Claude to help them hack into OpenAI | The VergeSkip to main contentThe homepageThe VergeThe Verge logo.The VergeThe Verge logo.TechReviewsScienceEntertainmentAIPolicyNotificationsNotificationsHamburger Navigation ButtonThe homepageThe VergeThe Verge logo.NotificationsNotificationsHamburger Navigation ButtonNavigation DrawerThe VergeThe Verge logo.Login / Sign UpcloseCloseSearchLightSystemDarkTechExpandAmazonAppleFacebookGoogleMicrosoftSamsungBusinessSee all techReviewsExpandSmart Home ReviewsPhone ReviewsTablet ReviewsHeadphone ReviewsSee all reviewsScienceExpandSpaceEnergyEnvironmentHealthSee all scienceEntertainmentExpandTV ShowsMoviesAudioSee all entertainmentAIExpandOpenAIAnthropicSee all AIPolicyExpandAntitrustPoliticsLawSecuritySee all policyGadgetsExpandLaptopsPhonesTVsHeadphonesSpeakersWearablesSee all gadgetsVerge ShoppingExpandBuying GuidesDealsGift GuidesSee all shoppingGamingExpandXboxPlayStationNintendoSee all gamingStreamingExpandDisneyHBONetflixYouTubeCreatorsSee all streamingTransportationExpandElectric CarsAutonomous CarsRide-sharingScootersSee all transportationFeaturesVerge VideoExpandTikTokYouTubeInstagramPodcastsExpandDecoderThe VergecastVersion HistoryNewslettersArchivesStoreVerge Product UpdatesSubscribeFacebookThreadsInstagramYoutubeRSSThe VergeThe Verge logo.Security researchers used Claude to help them hack into OpenAINotificationsNotificationsComments DrawerNotificationsCommentsLoading commentsGetting the conversation ready...AICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AINewsCloseNewsPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All NewsTechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechSecurity researchers used Claude to help them hack into OpenAIA three-person team of researchers used a corrupted image file and forum software to hack into OpenAI.A three-person team of researchers used a corrupted image file and forum software to hack into OpenAI.by Stevie BonifieldCloseStevie BonifieldNews WriterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Stevie BonifieldSep 18, 2026, 3:30 PM UTCLinkShareGiftImage: Cath Virginia / The Verge, Getty ImagesStevie BonifieldCloseStevie BonifieldPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Stevie Bonifield is a news writer covering all things consumer tech. Stevie started out at Laptop Mag writing news and reviews on hardware, gaming, and AI.A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, the Wall Street Journal reports. They were able to access OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to the Wall Street Journal’s sources.They stopped short of accessing internal code in Monorepo themselves, but sent a pull request from an employee’s Codex account to prove they gained access. They were able to get in through Discourse, the third-party service that hosts OpenAI’s community forums, by exploiting an issue with the system it uses to process HEIF images. According to Hacktron, Claude Opus 5 launched in the evening on July 24th, and by 10AM the next day they had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.Their HEIF Heist project took “only one or two days” to adapt to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using less than $3,000 in tokens, and to their knowledge, was only detected by one target, Shopify. The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron says OpenAI paid it $6,500 for finding the bug, but as Hacktron CTO Mohan Pedhapati said to the WSJ, “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.”Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.Stevie BonifieldCloseStevie BonifieldNews WriterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Stevie BonifieldAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIAnthropicCloseAnthropicPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AnthropicNewsCloseNewsPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All NewsOpenAICloseOpenAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All OpenAISecurityCloseSecurityPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All SecurityTechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechMost PopularMost PopularThe Apple Watch Series 12 is the start of a new wearable eraThe 2.5-hour AI-generated Odyssey movie is 2.5 hours too longThe iPhone 18 Pro’s big camera update is all about the small gainsVideoInside the suddenly explosive world of AI safetyYour robotaxi might be a narcThe Verge DailyA free daily digest of the news that matters most.Email (required)Sign UpBy submitting your email, you agree to our Terms and Privacy Notice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.Advertiser Content FromThis is the title for the native adMore in AIFlash floods can strike without warning — this new technology could change thatThe AI Superintelligence SlowdownClaude Code relaunches Projects to manage multiple AI agents in the cloudAI is feared globally as the destroyer of jobsPlayMicrosoft AI CEO says AI threats are real, and Anthropic is making it worseInside the suddenly explosive world of AI safetyFlash floods can strike without warning — this new technology could change thatMegan Wollerton11:00 AM UTCThe AI Superintelligence SlowdownSean HollisterSep 17Claude Code relaunches Projects to manage multiple AI agents in the cloudStevie BonifieldSep 17AI is feared globally as the destroyer of jobsThomas RickerSep 17PlayMicrosoft AI CEO says AI threats are real, and Anthropic is making it worseNilay PatelSep 17Inside the suddenly explosive world of AI safetyHayden FieldSep 17Advertiser Content FromThis is the title for the native adTop Stories11:00 AM UTCFlash floods can strike without warning — this new technology could change thatSep 17Inside the suddenly explosive world of AI safetySep 17Your robotaxi might be a narcSep 16The iPhone 18 Pro: an ambitious new camera on the marginsVideoSep 17The Apple Watch Series 12 is the start of a new wearable eraThe VergeThe Verge logo.FacebookThreadsInstagramYoutubeRSSContactTip UsCommunity GuidelinesArchivesAboutEthics StatementHow We Rate and Review ProductsCookie SettingsTerms of UsePrivacy PolicyYour California Privacy RightsYour Privacy ChoicesCookie NoticeAdChoicesLicensing FAQAccessibilityPlatform StatusPenske Media CorporationThe Verge is a part of PMX Global, LLC, a subsidiary of Penske Media Corporation.© 2026 VM Publishing, LLC. All rights reserved.Our SitesThe American PavilionARTnewsArt in AmericaArtforumArt Week NYCBeauty IncBillboardDeadlineDick Clark ProductionsThe DodoEaterFlow SpaceFNGold DerbyGolden GlobesThe Hollywood ReporterIndieWireLife is BeautifulPopsugarPunchSJ DenimRobb ReportRolling StoneSB NationSHE MediaShe KnowsSourcing JournalSoapsSporticoStyleCasterSXSWThrillistVarietyThe VergeVibeWWDNotifications DrawerThe VergeThe Verge logo.Sign in to see your notifications or create an account to join the conversation.Sign in

A team of three independent security researchers at Hacktron successfully hacked into OpenAI employee accounts by utilizing Anthropic’s Claude Opus 4.8 and 5, demonstrating new vulnerabilities related to AI interaction and third-party services. This infiltration was achieved by exploiting a corrupted image file and forum software. They managed to access OpenAI’s GitHub repository, referred to as the Monorepo, which sources suggest contains OpenAI’s algorithmic secrets. The researchers gained entry by exploiting a vulnerability within Discourse, the third-party service hosting OpenAI’s community forums, specifically targeting how the system processed HEIF images. Hacktron reported that the entire process, known as the HEIF Heist project, took less than seventy-two hours to gain access to the accounts. The researchers were able to prove their access by creating a pull request from an employee’s Codex account. Furthermore, the methodology was adaptable, allowing them to rapidly adapt the exploit to various companies including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, and ImageMagick, using fewer than three thousand dollars in tokens. Although the researchers exposed these vulnerabilities to Discourse and OpenAI, OpenAI reportedly paid a sum of six thousand five hundred dollars to Hacktron for discovering the bug. The Hacktron Chief Technology Officer noted that their capability stemmed primarily from the three researchers and their subscriptions to Claude and Codex, suggesting that they were not necessarily as powerful as some perceived threat actors.