Hacktron AI, a three-person security research startup led by founder Mohan Pedhapati, hacked OpenAI through a flaw in Discourse, third-party forum software that runs OpenAI's community site, TechCrunch and The Verge reported. Both outlets cited the Wall Street Journal's original report on the breach.

HEIC and HEIF image files uploaded to the forum were passed through ImageMagick and decoded with libheif, a library containing a heap buffer overflow that could be developed into remote code execution, according to TechCrunch. Hacktron found the entry point on July 25, and Discourse shipped a fix two days later.

Hacktron first tried building a working exploit with Claude Opus 4.8 and failed. Within hours of Anthropic releasing Claude Opus 5, the newer model found a way around OpenAI's address space layout randomization protections and completed the exploit, TechCrunch reported. The team used the resulting access to reach OpenAI's internal Monorepo GitHub repository and proved it by submitting a pull request from a compromised employee's Codex account, stopping short of viewing the proprietary code itself.

OpenAI confirmed the vulnerabilities were fixed and paid Hacktron a $6,500 bug bounty, according to both outlets.

The gap between "the previous model couldn't do this" and "the new model can" was measured in hours, not months. Any threat model that treats today's frontier model as a ceiling on what an attacker, or a red team, can automate needs to be revisited every time a lab ships a new flagship.