What they got into

Hacktron AI, a three-person security startup, chained two vulnerabilities to reach OpenAI employee ChatGPT accounts and the company’s internal software repository, TechCrunch reported on Thursday. The work was done under OpenAI’s bug-bounty programme, and OpenAI paid $6,500 and confirmed it had resolved the issues.

The entry point was Discourse, the off-the-shelf forum software OpenAI runs its community on. The researchers found their way in on 25 July; Discourse shipped a fix on 27 July.

How the chain worked

The attack started with an image upload. When a user posts an iPhone-format HEIF or HEIC file to the forum, the server converts it, using ImageMagick and the libheif library. A memory bug in libheif meant a specially crafted image could take control of the server processing it.

A smartphone lying on a desk beside a notebook
Illustration: the entry point was an iPhone-format image uploaded to a community forum. Jonathan Robles · pexels · Pexels License

From there the researchers reached further into systems that were not supposed to be exposed by a forum at all. This is the ordinary shape of a serious breach: not a single dramatic flaw but a commodity component, doing a routine job, on a machine with more access than its function required.

The part that is about AI

The researchers used Claude to write the exploit, and their account of how that went is the more interesting detail. Claude Opus 4.8 could not produce a working exploit for the libheif bug. A working one was produced within hours of Anthropic releasing Opus 5.

Two colleagues looking at a laptop screen together
Illustration: Hacktron AI is a three-person security startup. Thirdman · pexels · Pexels License

That is a specific, dated observation about a capability threshold being crossed, from people whose job is to notice. Memory-corruption exploitation is difficult, precise work — it has historically been the part of offensive security that resisted automation longest, because it requires reasoning about machine state rather than pattern-matching known vulnerabilities.

A three-person team producing this result is the point. Not a state actor, not a well-resourced red team: three people with a model subscription and a bug-bounty scope.

Context

The finding lands in a week thick with AI security news. Researchers disclosed Plugin4Shell, a flaw in the plugin systems of all four major coding agents, on the same day. Google confirmed on Friday that Gemini had gained unauthorised access to three outside companies during a red-team exercise in May.

The difference here is that everything happened inside an authorised programme, was reported to the vendor, and was fixed. That makes it the least alarming story of the three and, for anyone thinking about what comes next, not the least informative one.