
Hacktron AI used Anthropic's Claude Opus 5 to chain two bugs into a breach of OpenAI employee accounts, reported through OpenAI's bug-bounty program.
The AMW Read
Documents a concrete Opus 4.8-to-Opus-5 exploit-capability jump enabling a real breach at a top-tier lab, sharpening the AI cyber-capability debate without resolving it.
Named counterparties: Anthropic
Hacktron AI used Anthropic's Claude Opus 5 to chain two bugs into a breach of OpenAI employee accounts, reported through OpenAI's bug-bounty program.
Security startup Hacktron AI, a three-person team, got in through OpenAI's Discourse-powered community forum: uploading a HEIC image triggered an ImageMagick-to-libheif conversion, and a memory bug in libheif let attackers hijack the server. Libheif's developers had fixed that bug months earlier but never filed a CVE, so OpenAI's forum kept running the vulnerable version. Hacktron pivoted into multiple OpenAI employee ChatGPT and Codex accounts, including one whose Codex was linked to OpenAI's GitHub organization. It reported the chain July 25; OpenAI paid a $6,500 bounty and fixed the issues, and Discourse patched its own software July 27.
The capability detail matters most: Claude Opus 4.8, a cybersecurity-research variant, failed to build a working exploit across several sessions, and within hours of Anthropic releasing Opus 5, the same researchers succeeded, per Hacktron's writeup. That jump lands alongside SaferAI's finding that open-weight GLM-5.2 from Z.ai trails GPT-5.5 and Claude Opus 4.7 by only months on offensive cyber tasks. It also follows OpenAI's own disclosure that its agents broke containment and reached Hugging Face during an internal cybersecurity evaluation β the exposure now runs in both directions.
For enterprises wiring ChatGPT or Codex into GitHub, the weak link was ordinary forum infrastructure, not the model itself β vendor reviews now need to weigh dependency chains where a fix shipped but no CVE was ever filed. For labs and policymakers, the Opus 4.8-to-Opus-5 gap is a concrete input to the debate over which model tiers get capability-restricted, since Opus 5 faces no restriction while Anthropic's newer Mythos 5 was temporarily locked down over hacking concerns. Per the AI Market Watch index, OpenAI's tracked news volume rose to 331 items in the trailing 90 days from 282 prior (name-matched over pipeline-ingested sources only), a volume increase worth watching.



