Skip to main content

Three Guys, Two AI Subscriptions, One OpenAI Hack

How a Simple Flaw Unlocked OpenAI's Back Door

On July 23, a small team from security firm Hacktron AI stumbled onto something big. While probing Discourse, the forum software OpenAI uses, they found a vulnerability in how it handled certain image uploads. They turned to Claude Opus 4.8—a version reserved for cybersecurity pros—and asked it to craft an exploit. The first try fizzled. But that night, Anthropic rolled out Opus 5. By the next day, Claude had cracked it.

The flaw, tracked as CVE-2026-45788, let attackers access protected uploads if they knew the URL. No authentication needed. Discourse patched it on July 25, just hours after being notified.

But the real surprise came after. The researchers grabbed login tokens from OpenAI's forum server—and those tokens worked on ChatGPT. Not just any accounts, either. Employee accounts. And they opened the door to OpenAI's GitHub, too.

Into the Monorepo

With those tokens, the team could read files inside a massive software repository called "Monorepo." Insiders say it's where OpenAI keeps algorithm secrets to make models faster and more efficient. No model weights, but plenty of sensitive code.

They stopped as soon as they realized what they'd accessed. Before that, they'd submitted a document edit labeled "Hacktron AI Team PoC" as proof—OpenAI didn't accept it.

"We're Just Three People"

Mohan Pedhapati, Hacktron's CTO, didn't mince words. "I don't think we are smarter than foreign threats," he said. "We are just three people with Claude and Codex subscriptions."

His point? If a tiny team can slip past OpenAI's defenses, state-sponsored hackers—with far more resources—could do the same. The bounty of $6,500 (about 43,692 RMB) seems almost trivial next to that warning.

OpenAI has since tightened its security, but the incident raises uncomfortable questions. How many other AI giants are one clever prompt away from a breach? And if the tools to exploit them are now available to anyone with a subscription, where does that leave us?

Key Points:

  • Hacktron AI exploited a Discourse vulnerability (CVE-2026-45788) to access OpenAI's internal systems.
  • Login tokens from OpenAI's forum worked on ChatGPT employee accounts and GitHub.
  • Researchers accessed the "Monorepo" code repository but stopped upon realizing its sensitivity.
  • OpenAI paid a $6,500 bounty; Hacktron's CTO warns that state actors could replicate the attack.
  • The incident highlights growing risks as AI tools become more accessible to attackers.