Skip to content

Invest1 publisher2 min readPublished

Hacktron cleared roughly $3,500 on the exploit chain that reached OpenAI's GitHub

Three researchers at Hacktron AI used Claude to turn a bug in the Discourse software behind OpenAI's forum into access to employee Codex accounts and the private GitHub. OpenAI paid $6,500 for the chain, roughly twice what one unattributed account says it cost.

The Investor · Invest desk

Illustration accompanying Hacktron cleared roughly $3,500 on the exploit chain that reached OpenAI's GitHub

What happened

  • Three researchers at the startup Hacktron AI, Mohan Pedhapati, Harsh Jaiswal and Rahul Maini, used Anthropic's Claude to exploit a vulnerability in a third-party service and reach parts of OpenAI's internal systems.
  • According to Hacktron and a Wall Street Journal report, the team then reached several OpenAI employees' ChatGPT and Codex accounts and used one of them to get into OpenAI's private GitHub environment.
  • Hacktron reported the flaws to OpenAI and to Discourse, whose forum software carried the initial vulnerability, and OpenAI paid the team a $6,500 bug bounty.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost OpenAI is staffing this problem, not buying it off: after a separate internal breach earlier this year involving Hugging Face it put 25% of its production engineers solely on security defence, and that quarter of production engineering capacity is not shipping product.
  • exposure Hacktron said the potential scope was "huge" because compromised generative AI accounts sit close to GitHub, Slack and email, so every employer whose staff link those accounts inherits its vendors' parsing bugs inside its own authentication boundary.
  • contradiction OpenAI's note of only "limited reads" of private-repository metadata and Hacktron's account of the reach value the same incident differently, and the $6,500 was paid against the narrower of the two.
  • decision Bounty tiers were priced when exploit development took longer, so programme owners now have to decide what a two-day chain into a private monorepo is worth when $6,500 buys it.

The spend side comes from one line in the Indian Express report, carried without attribution, which says the three "hacked OpenAI with Opus 5 in 2 days for <$3000" [14]. Treat that as the cost and OpenAI's $6,500 payment [5] leaves about $3,500 [1], or roughly $1,167 a researcher [2], which across two days is about $583 each a day [3]. Gross return on spend, a little over two times [4]. For three people who can chain an image parser into a private code host, that day rate is below what the work bills at, and the published result is worth more to a cybersecurity startup than the payment.

The first bug was in someone else's code. Hacktron's account says the work began on July 23 on OpenAI's community forum, which runs Discourse, where the team found a flaw in the handling of HEIC/HEIF image files that researchers traced to the libheif library in the processing chain [3]. Hacktron reported the vulnerabilities to OpenAI and to Discourse [5]. The expensive step was the second one, where access to several employees' ChatGPT and Codex accounts carried into OpenAI's private GitHub environment [2], and the team proved it by creating a pull request through a compromised employee's Codex account [6].

This was an authorised test under a bug-bounty process, and there is no evidence Hacktron downloaded sensitive source code or accessed model weights [11]. The researchers said they stopped testing once they had established they could potentially reach sensitive internal material, and that they did not read or download OpenAI's private source code [9]. OpenAI said it fixed the vulnerabilities and revoked affected authentication tokens and sessions [10].

On the claim that frontier models are making offensive work cheaper, the evidence here is one chain against one target. The Indian Express report says the incident proves AI reduces the time required to move from finding a vulnerability to exploiting it, and that human researchers still drove the strategy and the operation [12]. The sequencing fits: attempts with Claude Opus 4.8 failed to produce a reliable exploit, and Anthropic released Claude Opus 5 on July 24 [4]. Two readings survive those facts. In one, the model release cut the cost of exploit development enough to change who can do this work. In the other, the binding weaknesses were a third-party image library and the credential path from an employee's Codex account into private GitHub, and both were there before any model touched them [3][2]. I lean to the second. What would move me is several bounty programmes reporting two-day chains from researchers without this team's track record.

What to watch

  • Whether Discourse publishes the scope of its fix for the HEIC/HEIF path, and how many other deployments ran the same image-processing chain.
  • Whether OpenAI reprices its bounty tiers for chains that begin in third-party software, after paying $6,500 for this one.
  • Whether Hacktron publishes a second chain against another AI lab, and discloses what that one cost to build.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories