Three people, two Claude models and a broken image file. That’s the whole toolkit a team of independent security researchers at Hacktron says it needed to get inside OpenAI employee accounts, and the job took less than 72 hours, according to a report in The Wall Street Journal.
The prize was access to OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to the Journal’s sources. Hacktron didn’t go rummaging through the internal code once it was in. Instead, the team sent a pull request from an employee’s Codex account to show it had the access, then stopped.
The way in wasn’t OpenAI’s own software
The entry point was Discourse, the third-party service that hosts OpenAI’s community forums. Hacktron found a flaw in the system Discourse uses to process HEIF images and exploited it with a corrupted image file.
The timeline is the part that should worry anyone running a public forum. According to Hacktron, Claude Opus 5 launched in the evening on July 24th. By 10AM the next day the team had used it to achieve RCE on Discourse Cloud and reach OpenAI’s instance. The researchers say they worked with both Anthropic's Claude Opus 4.8 and 5 during the project.
One bug, a long list of targets
Hacktron calls the project HEIF Heist, and OpenAI was only one name on the list. Adapting the technique to a new company took “only one or two days,” the team says, and it ran the same playbook against Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others.
The total bill for tokens came to less than $3,000. And of all those targets, Hacktron says only one, Shopify, detected the activity as far as the researchers know. That’s a detection rate most security teams would rather not see printed.
What it paid, and what it cost
The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed. OpenAI paid Hacktron $6,500 for finding the bug, the company says. Set that against the sub-$3,000 token spend and the payout roughly doubles the cost of the attack, which isn’t much of a margin for access to a repository described as holding a frontier lab’s algorithmic secrets.
Hacktron’s own read on the result is the least comfortable line in the story. “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions,” Hacktron CTO Mohan Pedhapati said to the WSJ.
Pedhapati’s point lands because of the arithmetic. If three people with consumer subscriptions can go from a model launch to remote code execution on a forum provider in a single night, the question for OpenAI and every other company outsourcing its community pages isn’t whether a better-resourced attacker could do the same. It’s how many already have without a pull request to announce it.