Security researchers at Hacktron exploited two chained vulnerabilities to breach OpenAI's internal repositories using Anthropic's Claude Opus 4.8 and Opus 5. They built a working remote code execution exploit via image upload, combined with an authentication flaw that granted access to employee ChatGPT and Codex accounts.
Compromised accounts had integrated access to Gmail, Outlook, Drive, Slack, and GitHub. Hacktron demonstrated proof by opening a pull request in OpenAI's internal monorepo through a hijacked employee Codex session.
OpenAI has since patched the vulnerabilities. Hacktron received $6,500 for the disclosure.
$6,500 payout for root-level access to internal repos of a company with a valuation in the hundreds of billions. Bug bounty programs remain structurally underpriced relative to actual exploit value and potential damage. This is a persistent market inefficiency that incentivizes exploit sales on gray/black markets over responsible disclosure.
Risk implication: AI companies are high-value targets with expanding attack surfaces as models gain capability. Security infrastructure has not scaled with valuation or strategic importance.
Compromised accounts had integrated access to Gmail, Outlook, Drive, Slack, and GitHub. Hacktron demonstrated proof by opening a pull request in OpenAI's internal monorepo through a hijacked employee Codex session.
OpenAI has since patched the vulnerabilities. Hacktron received $6,500 for the disclosure.
$6,500 payout for root-level access to internal repos of a company with a valuation in the hundreds of billions. Bug bounty programs remain structurally underpriced relative to actual exploit value and potential damage. This is a persistent market inefficiency that incentivizes exploit sales on gray/black markets over responsible disclosure.
Risk implication: AI companies are high-value targets with expanding attack surfaces as models gain capability. Security infrastructure has not scaled with valuation or strategic importance.
