Three independent researchers broke into openai employee accounts in under 72 hours using a crafted…
three independent researchers broke into openai employee accounts in under 72 hours using a crafted heif image uploaded as a forum avatar, then reached private code repositories and submitted an internal merge request as proof. the strongest frontier lab was breached without touching the model.
the attack surface is the community, not the weights.
Context
Hacktron AI's post of 13 September 2026 says that on 25 July 2026 its researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini chained a libheif heap overflow reached through ImageMagick in Discourse image uploads at community.openai.com with an OpenAI SSO flaw, taking over employee ChatGPT and Codex accounts. They reported it through OpenAI's Bugcrowd program. To prove access they prompted an employee's Codex to open a pull request in OpenAI's internal monorepo, and say they did so without accessing any internal code. They say OpenAI confirmed a fix about 14 hours after submission and awarded 6,500 dollars on 1 September, that Discourse patched it on 28 July, and that they used Claude models to develop the exploit.
This is the researchers' own account, a coordinated disclosure through a bug bounty, and not a blanket break-in. The under 72 hours is their stated span from discovery to repository access. The text read says image uploads, and forum avatar does not appear. It was a pull request opened through the employee's Codex, not a merge request and not merged. Private repositories means access, with no code read by their account. They are a team at a security company, and OpenAI is quoted only through their timeline. The attack surface is the community is the author's opinion.
Related work
- Earlier note on the Claude-assisted research ↗Same Hacktron research.
Watch next
- A first-party OpenAI statement and the Discourse advisory text.
Sources
- Hacking OpenAI (Hacktron AI, 13 Sep 2026)hacktron.ai
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 19 September 2026 at 02:45 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →