On July 25, 2026, a group of cybersecurity researchers from Hacktron AI discovered a significant vulnerability in OpenAI's systems, allowing them to access employee accounts and the company’s internal code repository. The attack was made possible by exploiting a flaw in how OpenAI’s community forum, hosted by the Discourse software, processed image files. The researchers used Anthropic’s Claude AI, specifically versions Opus 4.8 and Opus 5, to generate and refine the exploit code. The breach began on July 23 when the team identified a weakness in the libheif library, a tool used to handle HEIC image files, which was not updated with a critical security patch from a year earlier. This allowed them to execute remote code on OpenAI’s server and extract authentication tokens, some of which belonged to OpenAI employees. The stolen tokens granted the researchers access to ChatGPT and the “Monorepo,” a private code repository containing OpenAI’s algorithmic secrets. To demonstrate their access, the researchers submitted an innocuous pull request to the internal repository. OpenAI confirmed that the breach allowed limited reads of metadata and code changes in its private repositories. In response, the company mobilized a quarter of its engineers to address the vulnerabilities. OpenAI fixed the issue and revoked the compromised tokens and sessions on July 25, shortly after receiving the researchers’ report. Discourse, the software used by OpenAI for its forum, released a patch on July 27, including a new system to isolate image processing tasks, reducing potential risks. The incident was reported by The Wall Street Journal on September 17, 2026, and OpenAI reportedly paid the researchers $6,500 through its bug bounty program. One of the researchers noted the growing capabilities of AI tools, stating, “I don’t think we are as strong as the Chinese threat actors. We’re just three guys with Claude and Codex subscriptions.” The full technical report from Hacktron AI detailed the chain of events and identified similar vulnerabilities in the libheif library used by companies like Slack, Meta, Zoom, and Shopify. This breach occurred just two weeks after the Hugging Face intrusion, highlighting the increasing role of AI in breaking down technical barriers that once protected corporate systems. The entry point for the attack was OpenAI’s help forum, which allowed users to upload HEIC images. Discourse delegated the verification of these files to ImageMagick, which relied on the outdated libheif library. The researchers used Claude Opus 4.8 to analyze the library’s code and found a missing security fix. A buffer overflow vulnerability in the library allowed them to execute arbitrary code on the server. While Opus 5 made the exploit more effective, Opus 4.8 struggled with memory protections in place. The team bypassed Claude’s restrictions by making their test server appear as a “capture-the-flag” target, a common exercise in security testing. In response to this and the Hugging Face breach, OpenAI’s president and co-founder, Greg Brockman, stated that the company had reallocated 25% of its production engineers to strengthen its defenses.