On the morning of July 25, 2026, three Hacktron AI researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — completed a chain that had taken less than 72 hours to reach OpenAI from the outside. The entry point was community.openai.com, the Discourse forum. Once the forum was owned, a flaw in the OpenAI identity flow at auth.openai.com turned that foothold into takeover of any active forum member’s ChatGPT and Codex sessions. Using one employee whose Codex was linked to OpenAI’s GitHub organization, the team opened PR #1186742 in the private openai/openai monorepo, proving impact with a single harmless edit and then halting all testing.
Two links in the chain: image library and identity flow
A months-long HEIF Heist investigation lay behind the sprint. While mapping frontier AI labs, Hacktron noticed an odd fork in the forum’s image pipeline. Discourse used FastImage for most images, yet HEIC, HEIF and AVIF files, unsupported by FastImage, were handed to ImageMagick’s magick command for conversion. That path exposed the underlying libheif parser to attacker-controlled files. Any image anyone could upload therefore reached the deepest parser in the stack.
The root was a heap buffer overflow in libheif. An upstream code change a year earlier had not been tagged as a security fix and received no CVE, so Debian 12 and 13 never backported it in time. The Discourse Docker image, based on Debian 12, shipped libheif 1.19.7; even Debian 13 shipped 1.19.8 vulnerable at the time. Debian published its security update for 13 on August 8, 2026 as DSA-6417-1, while upstream moved to 1.23.4 by September 14, 2026, with additional fixes beyond 1.23.2.
Weeks of trials traced a clear capability curve for the models. On July 23 the team started an Opus 4.8 session against the Discourse Docker image and had it flag missing backports. On July 24 they built a working ImageMagick and libheif code execution exploit with ASLR disabled, but could not make it reliable with ASLR enabled under Discourse’s defaults. That evening Anthropic released Claude Opus 5. A fresh session produced a working ARM64 exploit on a local Mac within three hours, then ported it to the x86-64 and jemalloc layout used by Discourse. By 06:00 on July 25 local execution was confirmed.
Turning the prototype into remote success required steering around a refusal. Opus declined to write exploits for a remote instance, so the team proxied their own Discourse Cloud copy through rce.ee/ctf-forum and framed it as a capture-the-flag target. Left in an autonomous goal loop, the agent had achieved execution on Discourse Cloud and proved it by reading /etc/hosts by 10:00. The same script then yielded execution on OpenAI’s forum instance and administrative access. From there the identity flow was shown to allow account takeover of ChatGPT and Codex, and the report went to OpenAI.
Disclosure, demonstration and patch tempo
To show impact without touching sensitive code, the team never inspected the monorepo itself. They sent a prompt to the employee’s Codex to open a harmless pull request, then stopped. The disclosure clock was tight: a Bugcrowd submission between 08:00 and 10:00 UTC on July 25, updates that afternoon between 13:30 and 15:30 UTC adding the proof and direct pings to contacts at OpenAI, and a full halt by 15:30. OpenAI confirmed a fix at 22:49 UTC the same day, about fourteen hours after the first filing. The company paid a $6,500 bounty and noted the award reflected the OpenAI-side identity finding, since the Discourse instance itself sat outside the scope; testing against the externally hosted forum had been excluded.
Discourse itself patched with unusual speed. The report went via HackerOne on July 25, a reply came on Sunday July 26, a fix was ready Monday July 27 with ImageMagick sandboxed for defense in depth, and advisory GHSA-vhm9-85gw-x335 appeared July 28. For self-hosters the fix is not a web update alone: operators must run git pull and ./launcher rebuild app inside /var/discourse, or the underlying image stays vulnerable.
Cost and scale illustrate the multiplier AI provides. The initial chain took a few days of agent work and a few hours of human direction. The broader two-month HEIF Heist, spanning Slack, Meta, GitHub Enterprise, Ruby on Rails and Node.js frameworks such as Next.js, Astro and Gatsby, cost under $3,000 in tokens. Adapting the exploit to each new company typically took a day or two. Starting from a single image upload, the model turned memory corruption into a reliable leak or shell without knowing the exact libheif, libc or deployment, and it also assisted with privilege escalation and lateral movement when execution landed in a sandbox.
The sweep across the ecosystem was sobering. Any service that processes user-controlled .heic, .heif or .avif images and links a libheif family of 1.19.x through 1.23.x is potentially exposed if it lacks the latest upstream patches. Thousands of images were sent and parsers crashed repeatedly, yet only Shopify noticed the probe. That blind spot says as much about monitoring fatigue as about the bug. As xkcd #2347 Dependence warned, a neglected dependency deep down can topple even the largest lab.
In the closing notes Hacktron frames this as AI compressing scarce expertise into compute. What once demanded a resourced team and months to turn a known memory corruption issue into a reliable weapon now fits into days for a small crew. Opus 4.8 stalling against ASLR, Opus 5 breaking through within hours, and later jumps such as GPT-5.6 Sol succeeding blind against unfamiliar targets mark a steady acceleration. The work was not fully autonomous; human guidance stayed central, yet the volume one person can now oversee has grown dramatically. Defensive guidance is direct: disable untrusted HEIF and AVIF decoding where unneeded or isolate it in a hardened ephemeral sandbox, always install the latest libheif and libde265 from your distribution’s security channel, and use ImageMagick’s security policy to restrict formats and resources.
The ethical edge matters. A good-faith team proved the chain with a harmless pull request and immediate disclosure; the same steps in hostile hands could have meant silent copying of data with no alarms firing, just as the campaign showed elsewhere. Hacktron’s invitation reflects that urgency: to work with teams guarding frontier labs and other internet-critical software and to keep eliminating widely trusted flaws before exploitation becomes cheap. The team lists hello@hacktron.ai for contact and notes research continues across many such systems.
AI commentary
"This incident shows AI turning rare exploitation skill into compute and exposes how security through complexity no longer holds. What unsettles me most is that the chain stayed open for months and a single small image library held the whole ecosystem hostage."
AI assessment
That the chain worked end to end against a mature target such as OpenAI suggests the real risk across hundreds of products leaning on similar SSO and image paths is silent exfiltration we never see. Hacktron’s choice to prove impact with a harmless pull request was sound, yet the fact that the same steps could have copied data undetected highlights how weak detection and forensics still are.
On defense the lesson is blunt: do not accept obscure file formats by default and do not leave image pipelines internet-facing without isolation. For deep dependencies such as libheif, patching alone is insufficient; format restriction and sandboxing have become required depth, because the next memory flaw is already on its way.
Sources
5 links; no other published story cites them. Stories sharing a link do not confirm each other; a source's origin is not inferred from how often it is cited.
- @youtube.com YouTube — Wes Roth: OpenAI JUST got HACKED...
- @hacktron.ai https://www.hacktron.ai/blog/hacking-openai
- @businessinsider.com https://www.businessinsider.com/hacktron-ai-cybersecurity-startup-hack-openai-using-claude-2026-9
- @github.com https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f
- @thestateofai.com https://www.thestateofai.com/news/openai-hacked-claude-image-exploit
artificial intelligence · claude · breached · openai · hours · libheif · nodesdaily