Incident database
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Security researchers chained a Discourse/libheif image-processing flaw with an RCE exploit developed using Anthropic's Claude models to take over OpenAI employees' ChatGPT accounts via the community forum, then demonstrated access to an internal OpenAI GitHub repo by opening a pull request through a hijacked Codex account. OpenAI fixed the flaw within about 14 hours of disclosure and paid a $6,500 bug bounty.
Occurred 25 July 2026 · Disclosed 18 September 2026 · Record updated 18 September 2026
Impact
Attackers could take over any user's or employee's ChatGPT and Codex accounts via the community forum, potentially exposing connected services like GitHub, Slack, and email; researchers demonstrated access to an internal OpenAI repository before stopping.
Our coverage
IncidentsHacktron researchers chained an image-parsing flaw in OpenAI's Discourse forum with an AI-written exploit, then opened a pull request in an internal OpenAI repository.
18 Sept 2026
Sources
- theregister.comhttps://theregister.com/security/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts/5297517