White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing

The release of Claude Opus 5 gave the researchers exactly what they needed

by · TechRadar

News By Benedict Collins Published 18 September 2026

(Image credit: Shutterstock/Daniel Chetroni)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter


  • Security researchers used Claude Opus 5 to hijack an OpenAI employee's ChatGPT account
  • Exploit abused an image processing flaw on OpenAI community forums to gain full repo access
  • The entire timeline from vulnerability discovery to repo access took less than 72 hours

While taking part in an OpenAI bug bounty program, a group of Hacktron security researchers managed to compromise an internal OpenAI ChatGPT account and access internal company code on Github.

According to the Wall Street Journal, who first reported the incident, the researchers used a “special version” of Anthropic’s Claude made available to “qualified cybersecurity practitioners” to pull off the attack.

The researchers initially attempted to use Claude Opus 4.8 to create a breach, but faced multiple setbacks as the model “struggled across several sessions to produce a working exploit.” But the release of Opus 5 changed everything.

Latest Videos FromTechRadarWatch full video here:

OpenAI breach part of wider libheif exploit

The breach started with a libheif exploit that abuses a flaw in the .heic/.heif/.avif image file format decoder and encoder. While this exploit allowed Hacktron to breach OpenAI, libheif is also used across other platforms and software including Slack, Meta, GitHub Enterprise, Ruby on Rails, and more.

To start, the researchers first noted that the OpenAI community forum relies on the Discourse platform, which in turn relies on FastImage for image checks. But FastImage does not support .heif image files, and these are passed on to ImageMagick for conversion instead.

Developing a working code-execution exploit that abused this relation between ImageMagick and libheif with Opus 4.8 “wasn’t fruitful”, the researchers said, but on the same day Anthropic released Claude Opus 5.

With Opus 5, the researchers managed to create a working local remote code execution (RCE) using the same premise by setting an AI agent in a loop to exploit a local Discourse Cloud instance.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors