Exhibitor login
AI Insider 18 September 2026

Hacktron AI cracked OpenAI with Opus 5

Hacktron AI cracked OpenAI with Opus 5

Hacktron AI successfully intervened with OpenAI during a bug bounty program by combining two critical vulnerabilities. On September 18, it was revealed that the researchers had gained access to multiple ChatGPT accounts of OpenAI employees. This incident exposes important issues regarding AI safety, especially now that large AI companies are under pressure to secure their systems.

The researchers, who utilized Anthropic's AI models, managed to exploit the vulnerabilities through OpenAI's external software, Discourse. The attack began with an innocuous image upload, which led through a chain of tools to a vulnerability in libheif, a library involved in decoding image formats. Although the bug was fixed some time ago by the creators of libheif, it lacked an official CVE registration, leaving the vulnerability in use in OpenAI's Discourse installation.

After gaining access to the servers, the researchers were able to take over an employee account linked to OpenAI's GitHub organization, which increased the impact beyond initial expectations. This incident demonstrates how vulnerabilities in external software affect internal systems and also emphasizes the need for proper registration of security solutions. The successful hack with Opus 5 indicates an increasing ability of AI models to identify and exploit vulnerabilities, a development that highlights the necessity for stricter security measures within the sector.

OpenAI has since stated that the identified vulnerabilities have been resolved, coinciding with the growing pressure on tech companies to improve their security. The events surrounding Hacktron and the role of inexpensive and accessible AI tools underline the speed at which cyberattacks can be executed. This raises questions about how AI developers and platforms will handle the growing capabilities of models and the associated security risks.

Read the full article from AI Insider.