A team of three cybersecurity experts from Indian startup Hacktron AI used Anthropic’s Claude model to gain access to OpenAI employees’ internal accounts and the company’s private source code on GitHub. The attack exploited a known vulnerability in the libheif library, which Discourse uses to decode HEIC and HEIF image formats.
The flaw—a heap buffer overflow—existed in an outdated version of the software on Discourse servers. Researchers began analyzing the image pipeline on July 23 and had functional malicious code the next day, though it could only run with ASLR protection disabled.
Claude Opus 4.8 failed to create an exploit that bypassed ASLR. However, after the release of Opus 5 on July 24, the new model overcame this obstacle, allowing the team to proceed with the attack.
From account access to OpenAI’s internal code
Using the obtained credentials, the researchers accessed OpenAI’s private “Monorepo” repository, a key component of the infrastructure that speeds up the company’s models. Instead of examining the confidential code, they submitted a harmless pull request (number 1186742) solely to prove access.
“We’re just three guys with Claude and Codex subscriptions,” Mohan Pedhapati told the Wall Street Journal. According to the team, the entire process required only a few days of work from the AI agent and just a few hours of human time.
The HEIF Heist project and other victims
The OpenAI breach was part of a broader Hacktron AI investigation called “HEIF Heist,” which identifies vulnerabilities in image file processing across different services. The same technique had previously succeeded against platforms like Slack, Zoom, and Meta. The project lasted two months, involved three researchers, and cost less than $3,000 in AI tokens.
The researchers warned that artificial intelligence is eliminating traditional security protections based on software complexity, enabling tasks once limited to well-funded teams to be completed in days. “Security assumptions need to catch up with attackers’ capabilities,” they stated in their final report.
Reward and repercussions
OpenAI paid a $6,500 reward (approximately R$33,000) for the discovery, according to the Wall Street Journal. This incident adds to a series of security breaches involving both companies and intensifies the debate about the need for safeguards that allow AI to advance without exposing users to premature risks. Recently, Anthropic CEO Dario Amodei called for a coordinated slowdown in the development of frontier models.


