{"version":1,"type":"story","url":"https://digestai.news/story/hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine","json":"https://digestai.news/story/hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine.json","markdown":"https://digestai.news/story/hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine.md","slug":"hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine","headline":"Hacktron uses Claude Opus 5 to breach OpenAI staff accounts via chained flaws","summary":"Three researchers at the security firm Hacktron employed Anthropic's Claude Opus 5 to combine two vulnerabilities and gain access to OpenAI staff accounts for ChatGPT and Codex. The chain started with a remote‑code‑execution bug in the Discourse forum software (CVE‑2026‑32882, an out‑of‑bounds read in libheif) and continued through OpenAI's single sign‑on login system, allowing the team to take over internal accounts and submit a harmless pull request to an internal code repository. The entire process took under 72 hours. OpenAI confirmed a fix to the login flaw about 14 hours after the report and paid Hacktron a $6,500 bounty on September 1, noting the award recognized the OpenAI‑side finding, not the Discourse bug, which was outside its bug‑bounty program.\n\nClaude Opus 5, released on the evening of July 24, generated a working exploit within hours after earlier attempts with Claude Opus 4.8 failed. Anthropic’s safeguards were bypassed by directing the model at a test server and running it in an automated loop, though skilled human guidance remained essential. The incident highlights how AI‑assisted exploit generation can shorten attack timelines and underscores the need for up‑to‑date image‑processing libraries and careful SSO trust boundaries.","keyPoints":["Hacktron used Claude Opus 5 to exploit a Discourse libheif CVE‑2026‑32882 bug and OpenAI SSO, compromising staff ChatGPT and Codex accounts.","OpenAI fixed the login flaw 14 hours after the report and paid a $6,500 bounty on September 1.","The forum ran libheif 1.19.7; the vulnerability was patched in libheif 1.22.0 (May 2026) and later releases."],"whyItMatters":"The case shows AI models can accelerate the creation of functional exploits, raising urgency for secure SSO implementations and timely library updates across services.","category":{"slug":"enterprise","name":"Enterprise & Industry","url":"https://digestai.news/category/enterprise"},"entities":{"companies":["Anthropic","OpenAI","Hacktron","Discourse","Meta","Shopify"],"models":["Claude Opus 5","Claude Opus 4.8","GPT-5.6 Sol"],"people":[]},"firstPublishedAt":"2026-09-19T03:01:00Z","updatedAt":"2026-09-19T03:01:00Z","sourceCount":1,"hasPrimarySource":false,"sources":[{"outlet":"thehackernews.com","title":"Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws","url":"https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html","publishedAt":"2026-09-19T03:01:00Z","type":"press","primary":false,"lead":true}],"sourceNotes":null,"discussions":[],"thread":{"title":"Claude Opus 5 Account Breach Saga","url":"https://digestai.news/thread/researchers-used-claude-opus-5-to-compromise-openai-employee-accounts-report","storyCount":2},"cite":{"text":"Digest AI, \"Hacktron uses Claude Opus 5 to breach OpenAI staff accounts via chained flaws\", 19 September 2026, https://digestai.news/story/hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine","publisher":"Digest AI","title":"Hacktron uses Claude Opus 5 to breach OpenAI staff accounts via chained flaws","datePublished":"2026-09-19T03:01:00Z","url":"https://digestai.news/story/hacktron-uses-claude-opus-5-to-breach-openai-staff-accounts-via-chaine"},"generatedBy":"Written by Digest AI's editorial model from the linked sources; the sources are the record.","license":"Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse"}