2026-09-19-Sat · OpenAI · Claude · Astra

From Issue 48 (2026-09-19) · 11 stories in this issue

❯ Hacktron Used Claude to Chain Flaws Into an OpenAI Employee Account, Stirring Debate Over a $6,500 Bounty

Exploit ChainOn July 25, the three-person Hacktron AI team used Claude to construct exploit code, entering through an image-processing component used by OpenAI’s community forum and combining it with an authentication-token permission flaw. The researchers reached an employee-linked ChatGPT and Codex account and created one harmless pull request to demonstrate access to OpenAI’s private monorepo.

No Code TakenHacktron’s account does not support the shorthand that “Claude stole OpenAI source code.” The researchers said they did not download code, using the benign contribution only to verify repository permissions. The chain involved the forum’s Discourse environment and OpenAI’s single sign-on design. OpenAI fixed its side and paid a $6,500 bounty.

Scope DisputeOpenAI said testing the Discourse-hosted community had been excluded from the bug-bounty scope, so the award covered only the OpenAI-side issue. That explains the contractual boundary without eliminating the security exposure: an image-parser flaw in a third-party forum ultimately carried an identity token into a core employee development account.

Enterprise DefenseEnterprise security teams should recheck the permission radius of identity tokens whenever community, support or documentation systems share login infrastructure with internal development tools. AI helped the researchers assemble the exploit chain faster, but cross-system credentials and excessive authorization determined the blast radius. Bounty size also affects whether white hats keep disclosing high-value flaws.

▪ SIGNALClaude accelerated exploitation, but single sign-on determined how far the breach traveled; the dangerous part was not losing a forum, but letting its token reach a code repository.