
OpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts
The AMW Read
Adds cross-company portability detail (Slack, Meta, GitHub Enterprise) and cost figures to an already-reported OpenAI breach, illustrating agentic AI's dual-use offensive-security capability without resolving a new debate.
Named counterparties: Anthropic
OpenAI Patches Discourse Forum Bug After Researchers Used Claude Opus 5 to Breach Employee Accounts
A three-person team at security firm Hacktron used Anthropic's Claude Opus 4.8 and the newly released Claude Opus 5 to breach OpenAI employee accounts in under 72 hours, per The Wall Street Journal. They exploited a HEIF image-parsing flaw in Discourse, the third-party software hosting OpenAI's forums, reaching remote code execution on Discourse Cloud within hours of Opus 5's release and using that access to enter OpenAI's forum instance. From there they reached OpenAI's internal "Monorepo" GitHub repository, reportedly containing its algorithmic secrets, proving entry via a pull request from an employee's Codex account without pulling code themselves. OpenAI paid a $6,500 bug bounty and patched the flaw; the same technique, built for under $3,000 in tokens, was adapted within a day or two to also hit Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick β and only Shopify detected it.
OpenAI has faced a run of security and alignment disclosures this month; per the AI Market Watch index, name-matched OpenAI coverage in our pipeline rose to 332 items in the past 90 days from 282 prior β a coverage figure, not a census, but directionally consistent with a lab under compounding scrutiny. The notable twist: a rival's model, not OpenAI's own, chained a niche image-parsing bug into production access against a frontier lab's infrastructure, cheaply and repeatably across half a dozen major platforms β agentic coding models now function as an offensive-security force multiplier, not just a productivity tool.
For builders and investors, the takeaway is twofold: any company running Discourse or similar forum software should audit HEIF and other image-ingestion paths now, and the sub-$3,000 cost of compromising a top-five AI lab lowers the bar for attackers and defenders alike, reinforcing demand for AI-native red-teaming and bug-bounty tooling as a standing enterprise security line item.



