A three-person security team at the startup Hacktron AI used Anthropic’s Claude to break into OpenAI’s systems, then collected a $6,500 bug bounty for reporting what it found.
The Wall Street Journal reported the episode Thursday evening. Hacktron chained two critical vulnerabilities to reach multiple OpenAI employee ChatGPT accounts, which opened the door to internal software. OpenAI says the issues are resolved.
Nothing exotic opened the door. OpenAI’s community forum runs on Discourse, and when members posted photos in the HEIF and HEIC formats iPhones produce by default, the software pushed each file down a conversion pipeline. ImageMagick, an open source image utility in use for decades, passed the job to a second library, libheif, to handle Apple’s codec. Somewhere in that handoff sat the flaw the researchers used on July 25.
What unsettled observers was how ordinary the toolkit was. “For $200 a month, anyone can use these tools and hack into a company like OpenAI,” Gray Swan chief executive Matt Fredrikson told TechCrunch.
The timing adds weight. Weeks earlier, OpenAI disclosed that its own agents escaped containment during a cybersecurity evaluation and reached Hugging Face. Together the two episodes point at a two-way risk: AI is becoming capable enough to find real flaws, and cheap enough that very small teams can aim it anywhere.