Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    Hacktron Says It Hacked Openai in Under 72 Hours

    7 hours ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Hacktron Says It Hacked Openai In Under 72 Hours
    Hacktron Says It Hacked Openai In Under 72 Hours

    Hacktron AI says it managed to hack OpenAI in less than 72 hours. The security research team revealed that it chained two separate vulnerabilities to gain access to ChatGPT and Codex accounts belonging to OpenAI employees. To prove the access was real, the researchers used an employeeโ€™s Codex account to open a harmless pull request in OpenAIโ€™s internal monorepo rather than accessing sensitive code. The entire attack started with something that sounds relatively harmless: uploading an image.

    Hacktron shared the details in a technical write-up on September 13, while also summarizing the exploit chain on X.

    On July 25, our team hacked OpenAI.

    It took us less than 72 hours.

    Two vulnerabilities chained together gave us access to ChatGPT and Codex accounts belonging to OpenAI employees. We demonstrated the impact with a harmless PR in OpenAIโ€™s internal monorepo.

    The full chain:โ€ฆ

    — Hacktron AI (@HacktronAI) September 18, 2026

    According to the researchers, the chain looked like this:

    • HEIF upload โ†’ libheif heap overflow โ†’ remote code execution โ†’ OpenAI SSO flaw โ†’ ChatGPT/Codex takeover โ†’ connected GitHub โ†’ internal repository

    Key Takeaways

    • Hacktron AI says it compromised OpenAI systems in less than 72 hours.
    • The attack began with a HEIF image upload and a vulnerability in libheif.
    • An OpenAI SSO flaw allegedly allowed the researchers to move from the compromised forum to employee ChatGPT and Codex accounts.
    • A connected GitHub integration provided a path to demonstrate access to OpenAIโ€™s internal repository.
    • OpenAI says it fixed its side of the issue about 14 hours after the report and later paid Hacktron a $6,500 bounty.
    • The research highlights how AI can accelerate vulnerability research and exploit development, although Hacktron says human guidance was still necessary.

    The Hack Started With a Heif Image

    Hacktron was looking at the image-upload system used by OpenAIโ€™s community forum, which runs on Discourse. The researchers noticed that HEIC and HEIF images were processed differently from other image formats. Because Discourseโ€™s usual image-checking tool did not support HEIF, those files were passed to ImageMagick for conversion.

    That meant the uploaded files eventually reached libheif, an image-processing library responsible for handling the format. Hacktron then discovered a heap buffer overflow in the version of libheif used by the environment.

    According to the team, some security fixes had not been backported to the Debian package. This left the library vulnerable to a memory corruption attack that could provide out-of-bounds read and write capabilities. In other words, a specially crafted image could become much more than just an image.

    AI Helped Turn the Bug Into an Exploit

    This is where the story gets particularly interesting. Hacktron says it used AI models to help investigate and exploit the vulnerability.

    The researchers initially worked with Claude Opus 4.8, asking it to examine the installed libheif package for potential security problems. The model helped identify the relevant vulnerability, but getting a reliable exploit working proved difficult when ASLR was enabled.

    Then Anthropic released Claude Opus 5. Hacktron says the new model was able to produce a working ARM64 exploit within about three hours. The researchers then had it adapt the exploit to the x86-64 environment and the jemalloc configuration used by Discourse.

    By the morning of July 25, the team says it had confirmed remote code execution through an image upload. And that was only the beginning.

    The Openai SSO Flaw Changed Everything

    Getting code execution on the forum wasnโ€™t enough to reach OpenAI employee accounts. Hacktron discovered that the forum supported โ€œSign in with OpenAIโ€ through OpenAIโ€™s authentication infrastructure at auth.openai.com. The researchers believed this SSO setup could provide a route from a compromised forum account into other OpenAI services.

    According to Hacktron, they were able to confirm that assumption. The researchers said they took over an OpenAI employeeโ€™s ChatGPT and Codex accounts. That employeeโ€™s Codex account was connected to OpenAIโ€™s GitHub organization.

    Rather than digging through OpenAIโ€™s internal source code, Hacktron used the compromised Codex account to create a pull request in OpenAIโ€™s internal monorepo. The team described the pull request as a harmless proof of concept and stopped testing after demonstrating the access.

    OpenAI Fixed the Issue Within Hours

    Hacktron reported its findings to OpenAI through the Bugcrowd bug bounty program on July 25. According to the teamโ€™s timeline, OpenAI confirmed that its side of the issue had been fixed at around 22:49 UTC, roughly 14 hours after the initial report.

    The researchers also reported the underlying Discourse vulnerability to Discourse through HackerOne. Discourse responded the next day and had a fix ready by July 27. The company also added sandboxing for ImageMagick as an additional security measure.

    OpenAI later awarded Hacktron a $6,500 bounty for the OpenAI-side vulnerability. OpenAI clarified that testing against the Discourse-hosted community forum was outside the scope of its bug bounty program.

    The Bigger Concern Is AI-Assisted Hacking

    For Hacktron, this wasnโ€™t just another vulnerability disclosure. The researchers say the experiment shows how AI is changing the amount of time and expertise required to turn vulnerabilities into working exploits.

    Hacktron said the OpenAI and Discourse attack took a few days for an AI agent and only a few hours of human effort. Its broader HEIF Heist research reportedly involved three researchers and cost less than $3,000 in AI tokens.

    The team is careful to point out that the process wasnโ€™t completely autonomous. Human researchers still provided guidance and made important decisions during the operation. Still, the speed is notable. Hacktron argues that tasks that once required highly specialized security expertise and significant amounts of time can increasingly be accelerated by AI.

    The incident also shows why vulnerabilities in seemingly ordinary software can have much wider consequences when that software is connected to authentication systems and other services.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    victor
    • LinkedIn

    Victor Olaitan is a crypto writer who spends most of his time tracking charts, on-chain data, and market narratives as they happen. He is all about taking the fast-paced world of crypto and breaking it down into readable stories without all the noise

    Related Posts

    Cftc Sends Crypto Regulatory Framework To White House For Review

    CFTC Sends Crypto Regulatory Framework to White House for Review

    5 minutes ago
    Cftc Sends Crypto Regulatory Framework To White House Review

    CFTC Sends Crypto Regulatory Framework to White House Review

    1 hour ago
    Bitcoin Breaks $81k As Rebounding U.s. Yields Offset Oil Worries

    Bitcoin Breaks $81K as Rebounding U.S. Yields Offset Oil Worries

    2 hours ago
    Banks Surge On Eu Mica Crypto Provider List Update, Shares Up 23%

    Banks Surge on EU MiCA Crypto Provider List Update, Shares Up 23%

    3 hours ago
    Bitcoin Registers Fourth-Ever Bullish Cross, Boosting Bull-Case Momentum

    Bitcoin Registers Fourth-Ever Bullish Cross, Boosting Bull-Case Momentum

    4 hours ago
    Ethereum Institutional Signals Bolster Ethlabsโ€™ Case To Cut Block Times

    Ethereum Institutional Signals Bolster Ethlabsโ€™ Case to Cut Block Times

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • CFTC Sends Crypto Regulatory Framework to White House for Review
    • CFTC Sends Crypto Regulatory Framework to White House Review
    • Bitcoin Breaks $81K as Rebounding U.S. Yields Offset Oil Worries
    • Banks Surge on EU MiCA Crypto Provider List Update, Shares Up 23%
    • Bitcoin Registers Fourth-Ever Bullish Cross, Boosting Bull-Case Momentum
    • Ethereum Institutional Signals Bolster Ethlabsโ€™ Case to Cut Block Times
    • Dragonflyโ€™s Qureshi urges ending Zcash dev fund after 2028
    • Hacktron Says It Hacked Openai in Under 72 Hours
    • Analyst James Check: Bitcoinโ€™s cycle bottom could be near $58K
    • State-Linked Hackers Fuel 420% Jump in On-Chain Malware, Chainalysis Finds

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Bitpanda
    eToro Crypto 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Kraken Pro 300x250
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!