Updated
Updated · The Guardian · Sep 18
Hacktron Breaches Multiple OpenAI Accounts, Wins $6,500 Bounty
Updated
Updated · The Guardian · Sep 18

Hacktron Breaches Multiple OpenAI Accounts, Wins $6,500 Bounty

3 articles · Updated · The Guardian · Sep 18

Summary

  • Hacktron said it compromised multiple OpenAI employees’ ChatGPT accounts, then reached a stage where it could access a target’s software cache and potentially far more before reporting the flaws.
  • Claude helped the team get in through an OpenAI staff forum on Discourse, while OpenAI’s own GPT-5.6 Sol was used for much of the later work, showing how AI sharply cut the time needed for a once-complex attack.
  • A harmless GitHub pull request was used to demonstrate the exposure, and Hacktron said it accessed but did not download repository code; OpenAI said it fixed the exploited vulnerabilities.
  • The $6,500 bug-bounty case adds to a string of OpenAI safety incidents, after July’s Hugging Face hacking test and this week’s disclosure of six more concerning AI behaviors amid a widening debate over slowing AI development.

Insights

Why did OpenAI pay merely $6,500 after a rival AI successfully hijacked their employee accounts and infiltrated their internal systems?
How did an AI agent turn a simple forum image upload into a backdoor to OpenAI's most guarded internal code?
If AI can autonomously chain vulnerabilities to hack a leading AI lab in under 72 hours, is any enterprise network truly secure?