Researchers Breached OpenAI Systems Using Claude
Hacktron researchers chained vulnerabilities in July 2026 to access internal change proposals via OpenAI's forum.
Updated on Sept. 18, 2026 in Cybersecurity

Live Poll
Do you believe AI tools make cyberattacks against major online platforms significantly more likely today?
In late July 2026, researchers from Hacktron exploited a vulnerability in the libheif image processing tool to gain unauthorized access to an OpenAI employee account. The team used Anthropic's Claude Opus 5 model to analyze the system and identify the exploit.
Why it matters
This research highlights the risks of AI-assisted vulnerability discovery and the cascading security challenges posed by third-party software dependencies. It demonstrates how autonomous agents can accelerate the exploit development process, creating a new economic reality for cybersecurity researchers.
The attack sequence was completed in 72 hours by chaining vulnerabilities through the libheif library, a tool used by OpenAI's Discourse forum software. The process demonstrates how AI can automate the complex task of identifying and weaponizing software vulnerabilities.
The players
Hacktron
A research group focused on identifying system vulnerabilities and testing exploit economics.
OpenAI
A research laboratory and product company focused on large-scale AI models and deployment.
Anthropic
A developer of AI models including Claude, known for research into model safety and reasoning.
Discourse
An open-source forum platform used by numerous organizations for community communication.
The details
Researchers utilized Anthropic's Claude Opus 5 — a large language model capable of reasoning and code analysis — to audit the target software for flaws. By exploiting a vulnerability in libheif, a library for decoding High Efficiency Image File Format images, the team was able to gain entry into the environment. The breach allowed the researchers to access internal system change proposals before OpenAI subsequently deployed a patch for the Discourse platform.
Timeline
Late July 2026: Researchers conducted the security assessment.
September 18, 2026: Publication of the security breach details.
The Tech Race
The use of an LLM to accelerate the exploit of a common library like libheif highlights the shifting speed of vulnerability discovery. This follows a growing trend of security researchers using generative AI to outpace standard defensive patch cycles on widely adopted software platforms.
The vulnerability exploited in this breach has been patched, meaning users of the affected forum software are no longer at risk from this specific vector. Organizations relying on third-party libraries should monitor software supply chain advisories to ensure they remain updated against automated exploits.
The takeaway
This event demonstrates that AI-driven exploitation is no longer theoretical, forcing companies to move faster than the 72-hour attack window demonstrated here. Observers should track the next iteration of open-source vulnerability audits conducted by AI-first research firms.
Further reading
For broader trends in enterprise digital defense, see our coverage of Cybersecurity.
Live Poll
Do you believe AI tools make cyberattacks against major online platforms significantly more likely today?









