THE TELL

Three guys, a broken photo, and $3,000 of Claude tokens got inside OpenAI

The way into one of the most guarded companies in tech was an image file uploaded to a discussion forum. It took under 72 hours.

A team of three independent security researchers at a firm called Hacktron says it got into OpenAI employee accounts in less than 72 hours, using Anthropic's Claude Opus 4.8 and 5. The Wall Street Journal reported it; The Verge wrote it up on September 18. They ended up inside OpenAI's GitHub repository, the one called "Monorepo" — which, according to the Journal's sources, holds "OpenAI's algorithmic secrets."

They did not read the code. To prove they were in, they sent a pull request from an employee's Codex account — roughly the software equivalent of leaving a signed note on someone's desk instead of emptying the drawers. The door was not OpenAI's own. It was Discourse, the outside company that runs OpenAI's community forums, and a flaw in how it processes HEIF images — the photo format your phone saves pictures in by default.

What it means

Here is the part that should make anyone uneasy. The same trick, which Hacktron calls the HEIF Heist, took "only one or two days" to adapt from one company to the next: OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others. The total AI bill was under $3,000 in tokens — less than a second-hand car. And of that whole list, by Hacktron's own account, exactly one target spotted them: Shopify.

So the break-in is not really the story. The detection rate is. A weekend-sized project walked through some of the best-defended systems in tech, and almost nobody noticed it happening. When a company later says it found no evidence of intrusion, this is what that sentence is now worth.
Share this

The timeline is the other uncomfortable detail. Claude Opus 5 launched in the evening on July 24th. By 10AM the next day, Hacktron says, it had used the model to get remote code execution on Discourse Cloud — that means making someone else's server run your instructions instead of its own — and had reached OpenAI's instance. Less than a day between a model shipping and that model being pointed at the company next door.

The money ends up almost comic. OpenAI paid Hacktron $6,500 for finding the bug, and the vulnerabilities reported to Discourse and OpenAI have since been fixed. So a full campaign against a dozen named targets cost less in tokens than the reward for one of them. Hacktron CTO Mohan Pedhapati told the WSJ: "I don't think we are as strong as Chinese threat actors… We're just three guys with Claude and Codex subscriptions." That is not modesty. That is the ceiling being described by the people standing under it.

Who it matters to

Anyone who has ever signed up to a company's community forum or support site with the same email and password habits they use for work, their exchange account or their first few thousand in crypto — because the weak point here was not the famous company, it was the small service bolted onto it. And anyone in their twenties deciding what to actually learn: if three people with two AI subscriptions can do this over a weekend, the people who can find these holes first — and the people who can tell when someone is already inside — are the ones companies will be short of. Shopify's only advantage in this story was that it was watching.

What's next

The source names no hearing, no report and no deadline, so we won't invent one. What is settled: the flaws at Discourse and OpenAI are fixed, and OpenAI paid $6,500. What is open: of the targets Hacktron named — Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick — only Shopify is said to have detected anything. Watch whether any of the others confirms it was tested, and whether any of them says it saw it. Nobody has put a date on that.

One detail to hold on to

Shopify's win wasn't that it was unbreakable. It was that it noticed. Every other name on that list learned about this from a write-up. So the real split now isn't between companies that can be broken into and companies that can't. It's between the ones who find out and the ones who get told.

Sources: The Verge, September 18, 2026 (Stevie Bonifield), reporting The Wall Street Journal's account and Hacktron's own timeline.

Why we ran this8/10

Три человека с подпиской на Claude за трое дней и 3000 долларов пробрались в закрытый репозиторий OpenAI и в системы Meta, Slack и GitHub — и почти никто из них этого не заметил, то есть дешёвый взлом с помощью ИИ уже работает против самых защищённых компаний мира.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Loudoun County cut property taxes 30%. I…Next: Microsoft's own words: a "doom loop" that … →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X