Researchers breached OpenAI accounts in 72 hours, report says
Three Hacktron researchers reportedly chained an image-processing bug with an identity flaw to reach ChatGPT and Codex accounts, using Anthropic's Claude during the effort.

Three security researchers at cybersecurity startup Hacktron reportedly gained access to multiple OpenAI employee accounts and reached an internal code repository within 72 hours, according to a CryptoSlate report. The work took place in July.
The researchers are said to have combined an image-processing vulnerability with a weakness in OpenAI's identity infrastructure to obtain access to several employees' ChatGPT and Codex accounts. One of the compromised Codex accounts was connected to OpenAI's GitHub, the report states.
Anthropic's Claude model was used to assist the researchers during the operation, per the report, which frames the episode as a demonstration of how AI assistants can speed up offensive security work.
Why it matters
The reported chain links two separate weaknesses rather than a single critical flaw, a pattern that is common in intrusion research and difficult to defend against because each component may appear low-risk on its own. It also adds to ongoing scrutiny of how AI vendors secure employee identities and internal code repositories, and of the dual role AI models can play in both defensive and offensive security testing.