A team of security researchers used Anthropic’s Claude Opus 5 to chain three vulnerabilities and gain access to OpenAI’s private code repository in less than 72 hours.
OpenAI paid $6,500 for the discovery after the researchers, who are affiliated with security start-up Hacktron AI, demonstrated access without examining sensitive source code.
The first weakness was found in the vulnerable ‘libheif’ library used by Discourse forum software. It enabled remote code execution on the forum, allowing the team to move through a flaw in OpenAI’s single sign-on (SSO) process.
The researchers then took control of an employee’s ChatGPT account and reached the Codex environment connected to OpenAI’s GitHub organisation. That provided access to the openai/openai monorepo.
To show they had successfully entered the repository, they opened a harmless pull request before stopping their investigation.
The work was carried out in late July. The team reported the findings through OpenAI’s Bugcrowd programme on July 25, and the vulnerability was fixed that day. Discourse published its advisory on July 28, assigning the flaw a Common Vulnerability Scoring System (CVSS) severity rating of 8.8.
The incident became public on Sept. 17 after being reported by the Wall Street Journal.
The researchers initially tested Claude Opus 4.8 but found it unreliable. After switching to Claude Opus 5, which was released on July 24, they produced a working ARM64 exploit within hours and then adapted it for x86-64 and jemalloc environments.
Developing exploits involving memory corruption has traditionally been specialist work that can take skilled human researchers weeks. In this case, the full sequence was completed in under three days.
The episode highlights how artificial intelligence could shorten the distance between identifying a software flaw and turning it into a usable exploit. It does not mean OpenAI is unusual in having vulnerabilities, as software companies regularly encounter them.
The wider cyber security impact is also being seen in cryptocurrency. Chainalysis reported this week that attackers are publishing malware instructions to public blockchains 440% more often than a year ago. Daily malicious onchain writes have risen from 2.06 to 11.1.
The firm linked the increase to mid-2025, when open-weight Chinese models were released without meaningful safeguards against generating malicious code. It described the method as “blockchain dead drops” command-and-control instructions stored on a ledger that cannot be seized or taken offline.
By the second quarter of 2026, state-linked operators from North Korea and Iran accounted for roughly two-thirds of new activity and about half of all activity.
Researchers monitoring North Korea’s Kimsuky found local large language model (LLM) platforms, including Ollama, GPT4All and Msty, installed on the group’s infrastructure alongside AI-generated phishing decoys targeting virtual asset and financial investment organisations.
Blockaid counted 212 onchain exploits worth $1.1 billion as AI and wallet attacks accelerated. Defillama described April 2026 as crypto’s most-hacked month on record, with 30 incidents.
Coinbase has warned that bug reports could triple as AI-generated submissions overwhelm disclosure programmes. The $6,500 bounty illustrates how a relatively small payment can uncover a three-stage route into a major technology lab.
Exploit development is increasingly becoming a commodity service. Anthropic remains a private company, although crypto traders have assigned its Claude business an implied valuation.
