Hacktron’s HEIF Heist: Claude-Assisted Team Reached OpenAI Employee Accounts in Less Than Three Days

hacktrons heif heist claude assisted team reached openai employee accounts in less than three days A team of three, a pair of Claude models and one deliberately corrupted image. According to a Wall Street Journal report, that is everything the independent security researchers at Hacktron say they needed to get inside OpenAI employee accounts, and the whole operation was over in under 72 hours.

A team of three, a pair of Claude models and one deliberately corrupted image. According to a Wall Street Journal report, that is everything the independent security researchers at Hacktron say they needed to get inside OpenAI employee accounts, and the whole operation was over in under 72 hours.

What was at stake was OpenAI’s GitHub repository, known as “Monorepo,” which the Journal’s sources describe as holding “OpenAI’s algorithmic secrets.” Once inside, Hacktron did not poke around in the internal code. To prove the access was real, the team submitted a pull request from an employee’s Codex account and then called it a day.

The door wasn’t in OpenAI’s own code

The way in ran through Discourse, the third-party platform that hosts OpenAI’s community forums. Hacktron identified a weakness in the component Discourse uses to handle HEIF images and triggered it with a malformed image file.

The timing is what should give anyone operating a public forum pause. Hacktron says Claude Opus 5 went live on the evening of July 24th. By 10AM the following morning, the team had used it to achieve RCE on Discourse Cloud and reach OpenAI’s instance. The researchers say they relied on both Anthropic's Claude Opus 4.8 and 5 over the course of the project.

A single flaw, many doors

Hacktron has named the effort HEIF Heist, and OpenAI was just one entry on a longer target list. The team says porting the technique to a fresh company took “only one or two days,” and it repeated the same approach against Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others.

Total token spend came in under $3,000. Across all of those targets, Hacktron says that, as far as the researchers are aware, only one company, Shopify, noticed what was happening. That is a detection rate most security teams would not want on the record.

The payout versus the price tag

The flaws Hacktron disclosed to Discourse and OpenAI have since been patched. OpenAI paid Hacktron $6,500 for the find, according to the company. Measured against a token bill of less than $3,000, the reward is roughly double what the attack cost, a thin margin for a way into a repository said to contain a frontier lab’s algorithmic secrets.

Hacktron’s own assessment is the most unsettling line of the whole story. “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions,” Hacktron CTO Mohan Pedhapati told the WSJ.

The math is what gives Pedhapati’s remark its weight. When three people on consumer subscriptions can move from a model’s launch to remote code execution on a forum provider overnight, the real question for OpenAI and every other company that outsources its community pages is not whether a better-funded adversary could pull off the same thing. It is how many have already done so without filing a pull request to say hello.