White Hat Hackers Breach OpenAI Staff ChatGPT Accounts Using Claude, Claim $6,500 Bounty

On September 18, The Wall Street Journal reported that independent security researchers breached an OpenAI employee’s ChatGPT account via Anthropic Claude, gaining entry to the firm’s private software code repository.
The team, representing security firm Hacktron AI, had previously participated in OpenAI’s bug bounty program. Upon identifying the vulnerability, they promptly reported it to OpenAI, which awarded them a $6,500 bounty (approximately 43,692 RMB).
The Vulnerability Resided in Discourse, with Tokens Valid on ChatGPT
The intrusion commenced on July 23. Hacktron researchers identified a flaw in Discourse’s handling of specific image files and utilized a specialized version of Claude Opus 4.8, reserved for qualified cybersecurity professionals, to generate exploit code. The initial attempt failed; however, following Anthropic’s release of Opus 5 that night, Claude successfully exploited the vulnerability the next day.
The exploited flaw, designated CVE-2026-45788, is an unrestricted upload vulnerability within Discourse’s secure upload feature. Attackers can expose protected content if they possess the corresponding URL, bypassing authentication requirements for remote attacks. Discourse confirmed it received notification on July 25 and patched the issue immediately.
The attack enabled researchers to access the Discourse server hosting OpenAI’s forum and retrieve account login tokens. Unexpectedly, these tokens functioned on ChatGPT, including for OpenAI employees, and granted access to OpenAI’s GitHub services.
Consequently, researchers accessed files within a major software repository known as "Monorepo." According to insiders, Monorepo contains the algorithmic secrets that enable OpenAI’s models to operate with greater speed and efficiency, though it excludes model weights. The researchers halted the intrusion upon realizing they could access sensitive data, having previously submitted a document modification request labeled "Hacktron AI Team PoC" as proof (which was rejected).
"We Are Simply Three Individuals with Claude and Codex Subscriptions"
Mohan Pedhapati, CTO of Hacktron AI, stated that the incident demonstrates how state-sponsored advanced cyber teams have genuine opportunities to窥视 American AI secrets: "I do not believe we are smarter than foreign threats. We are merely three people with Claude and Codex subscriptions."
Related article
Cognition AI in Funding Talks as Valuation Soars to $40 Billion
Cognition, the creator of the acclaimed AI coding assistant Devin, has captured substantial interest from investors. Industry sources indicate the company is currently negotiating a fresh funding round, with projections suggesting its valuation will
OpenAI Unveils Base Large Model Under New Pre-training Project Doug
As artificial intelligence technology continues to evolve, the industry's focus on the underlying architecture of foundational large models has never waned. Recently, an X user who has long tracked developments in large models revealed that OpenAI is
Deltek Study: 91% of Firms Call AI Critical to Success
Deltek research reveals that while project firms anticipate higher profits, execution gaps currently limit the measurable impact of AI. Credit: Nitat Termmee/Getty ImagesAccording to Deltek’s Heather Larkin, leading firms are successfully linking dat
Related Special Topic Recommendations
Comments (0)
0/500

On September 18, The Wall Street Journal reported that independent security researchers breached an OpenAI employee’s ChatGPT account via Anthropic Claude, gaining entry to the firm’s private software code repository.
The team, representing security firm Hacktron AI, had previously participated in OpenAI’s bug bounty program. Upon identifying the vulnerability, they promptly reported it to OpenAI, which awarded them a $6,500 bounty (approximately 43,692 RMB).
The Vulnerability Resided in Discourse, with Tokens Valid on ChatGPT
The intrusion commenced on July 23. Hacktron researchers identified a flaw in Discourse’s handling of specific image files and utilized a specialized version of Claude Opus 4.8, reserved for qualified cybersecurity professionals, to generate exploit code. The initial attempt failed; however, following Anthropic’s release of Opus 5 that night, Claude successfully exploited the vulnerability the next day.
The exploited flaw, designated CVE-2026-45788, is an unrestricted upload vulnerability within Discourse’s secure upload feature. Attackers can expose protected content if they possess the corresponding URL, bypassing authentication requirements for remote attacks. Discourse confirmed it received notification on July 25 and patched the issue immediately.
The attack enabled researchers to access the Discourse server hosting OpenAI’s forum and retrieve account login tokens. Unexpectedly, these tokens functioned on ChatGPT, including for OpenAI employees, and granted access to OpenAI’s GitHub services.
Consequently, researchers accessed files within a major software repository known as "Monorepo." According to insiders, Monorepo contains the algorithmic secrets that enable OpenAI’s models to operate with greater speed and efficiency, though it excludes model weights. The researchers halted the intrusion upon realizing they could access sensitive data, having previously submitted a document modification request labeled "Hacktron AI Team PoC" as proof (which was rejected).
"We Are Simply Three Individuals with Claude and Codex Subscriptions"
Mohan Pedhapati, CTO of Hacktron AI, stated that the incident demonstrates how state-sponsored advanced cyber teams have genuine opportunities to窥视 American AI secrets: "I do not believe we are smarter than foreign threats. We are merely three people with Claude and Codex subscriptions."
Cognition AI in Funding Talks as Valuation Soars to $40 Billion
Cognition, the creator of the acclaimed AI coding assistant Devin, has captured substantial interest from investors. Industry sources indicate the company is currently negotiating a fresh funding round, with projections suggesting its valuation will
OpenAI Unveils Base Large Model Under New Pre-training Project Doug
As artificial intelligence technology continues to evolve, the industry's focus on the underlying architecture of foundational large models has never waned. Recently, an X user who has long tracked developments in large models revealed that OpenAI is
Deltek Study: 91% of Firms Call AI Critical to Success
Deltek research reveals that while project firms anticipate higher profits, execution gaps currently limit the measurable impact of AI. Credit: Nitat Termmee/Getty ImagesAccording to Deltek’s Heather Larkin, leading firms are successfully linking dat





Home






