Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Hackers Breach OpenAI Systems Using AI-Assisted Exploit

Published 18 September 2026

Security researchers from Hacktron AI breached OpenAI's systems in July 2026, exploiting vulnerabilities in a third-party forum to access employee accounts and the company's internal code repository, according to a disclosure by the team. The researchers, operating under OpenAI's authorized bug bounty program, reported the incident on September 18, 2026, detailing an attack chain that began on July 23 and concluded with proof of access on July 25. The breach started with a flaw in the image-processing system of Discourse, the platform hosting OpenAI's community forum. Hacktron AI researchers uploaded a malicious HEIF image file, which triggered a heap buffer overflow in an outdated version of the libheif library. This memory corruption vulnerability allowed them to achieve remote code execution on the forum's server. From there, the team discovered a single sign-on (SSO) misconfiguration. By hijacking session tokens from the compromised forum server, they were able to impersonate an OpenAI employee and access linked services, including ChatGPT and Codex accounts.

0:00 / 0:00