Skip to main content
Back to News
OpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts
Technology
2 min read
US

OpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts

The AMW Read

Adds cross-company portability detail (Slack, Meta, GitHub Enterprise) and cost figures to an already-reported OpenAI breach, illustrating agentic AI's dual-use offensive-security capability without resolving a new debate.
NoveltySignificance
Foundation Models Β· Case StudiesSafety / Alignment
OpenAI
OpenAI

Foundation Models / LLMs

View Company Profile

Named counterparties: Anthropic

OpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts

A three-person team at security firm Hacktron used Anthropic's Claude Opus 4.8 and the newly released Claude Opus 5 to breach OpenAI employee accounts in under 72 hours, per The Wall Street Journal. They exploited a HEIF image-parsing flaw in Discourse, the third-party software hosting OpenAI's forums, reaching remote code execution on Discourse Cloud within hours of Opus 5's release and using that access to enter OpenAI's forum instance. From there they reached OpenAI's internal "Monorepo" GitHub repository, reportedly containing its algorithmic secrets, proving entry via a pull request from an employee's Codex account without pulling code themselves. OpenAI paid a $6,500 bug bounty and patched the flaw; the same technique, built for under $3,000 in tokens, was adapted within a day or two to also hit Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick β€” and only Shopify detected it.

OpenAI has faced a run of security and alignment disclosures this month; per the AI Market Watch index, name-matched OpenAI coverage in our pipeline rose to 332 items in the past 90 days from 282 prior β€” a coverage figure, not a census, but directionally consistent with a lab under compounding scrutiny. The notable twist: a rival's model, not OpenAI's own, chained a niche image-parsing bug into production access against a frontier lab's infrastructure, cheaply and repeatably across half a dozen major platforms β€” agentic coding models now function as an offensive-security force multiplier, not just a productivity tool.

For builders and investors, the takeaway is twofold: any company running Discourse or similar forum software should audit HEIF and other image-ingestion paths now, and the sub-$3,000 cost of compromising a top-five AI lab lowers the bar for attackers and defenders alike, reinforcing demand for AI-native red-teaming and bug-bounty tooling as a standing enterprise security line item.

#OpenAI #Anthropic #ClaudeOpus5 #AISecurity #BugBounty #AIAgents

#OpenAI#Anthropic#Claude Opus 5#Discourse#bug bounty#AI security#related:Anthropic

How This Connects

Based on Foundation Models Β· Case Studies

  1. 20h agoAnthropic Weighs New Model Release Ahead of IPO as OpenAI's Astra Narrows Its Enterprise LeadAnthropic
  2. 1d agoZhipu AI (ζ™Ίθ°±) has raised roughly $5 billion to bankroll its next GLM models and a self-training R&D pipeline.Zhipu AI
  3. 1d agoOpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts Β· THIS ARTICLE
  4. 1w agoAnthropic CEO Dario Amodei urges deliberate pace adjustment in frontier AI developmentAnthropic
  5. 2w agoOpenAI launches Astra, its most capable model, as opaque-reasoning and AGI claims fuel a fresh safety debate.OpenAI
  6. 2w agoOpenAI Astra's opaque recurrence technique draws AI safety alarmOpenAI

Related News

More news from OpenAI

Stay updated with the latest news and announcements from OpenAI.

View all OpenAI news

Discover AI Startups

Explore 5,000+ AI companies with VC-grade analysis, funding data, and investment insights.

Explore Dashboard