📈 Get daily crypto insights that make you smarter about your money

Claude AI Helped Researchers Breach OpenAI in 72 Hours — and the Crypto Security Math Just Changed

Three security researchers used Anthropic’s Claude AI to breach OpenAI accounts and reach an internal code repository in under 72 hours — and the part of the story that should worry crypto holders is not the target, but the speed. Work that once took months of specialist labor now takes days, and the security firms guarding blockchain protocols are taking note.

By Keisha Williams | September 19, 2026

The Hook: From a Forum Photo to OpenAI’s Private Code

Cybersecurity startup Hacktron disclosed this week that its researchers chained two weaknesses in July to reach OpenAI’s internal software environment, according to CryptoSlate. First, an image-processing flaw: OpenAI’s Discourse community forum processed HEIC and HEIF photos through ImageMagick and the underlying libheif decoding library, and a bug there — a heap buffer overflow — let a malicious image execute code on the server. Second, a flaw in OpenAI’s identity infrastructure let the team move from forum administrator access into employee ChatGPT and Codex accounts.

One compromised employee had connected Codex to OpenAI’s GitHub organization. That created a path into the company’s private openai/openai monorepo, where the researchers stopped, instructing the hijacked account to create a harmless pull request as proof. They did not inspect proprietary source code. OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and paid Hacktron a 6,500 USD bounty.

The Evidence: Where the Old Model Failed, the New One Succeeded

The technical timeline is what makes the incident a landmark. Hacktron began probing the forum’s image pipeline on July 23. It first gave Claude Opus 4.8 a copy of the forum’s Docker image and asked it to hunt for weaknesses in the installed libheif package. The model found the missing fixes and by July 24 had produced an exploit that worked — but only when a built-in protection called address space layout randomization, which scrambles memory locations to blunt attacks, was switched off. Against the forum’s normal configuration, the exploit failed again and again.

Then Anthropic released Claude Opus 5. In a fresh session, the new model produced a working exploit for an ARM64 Mac in about three hours. Asked to adapt it to the x86-64 architecture the forum actually ran, the researchers had a reliable weapon by 6 a.m. on July 25 — roughly 72 hours after the first probe. When the team later put the model in an autonomous loop against a copy of the forum it owned, Claude initially refused to attack a remote system. The researchers reframed the test to look like a capture-the-flag security exercise; four hours later, the agent had reproduced the breach on its own.

The Core Conflict: AI Cuts Both Ways for Crypto Security

Hacktron co-founder Mohan “s1r1us” Pedhapati put it plainly: AI is reducing the amount of scarce expertise needed to develop exploits, and work that once took months can now take days. The company stressed the operation still depended on skilled human guidance — this was not fully autonomous hacking. But the direction matters more than the caveat.

For the crypto industry, the arithmetic is uncomfortable. Smart contracts, bridges and wallet software are attacked by the same class of memory and logic bugs the AI hunted in this test — and bug bodies in blockchain pay far better than 6,500 USD, which cuts both ways. The same models that help auditors find flaws before launch can help attackers find them after. Blockchain security firms have been warning about this gap for months, and Ethereum co-founder Vitalik Buterin has repeatedly argued that defensive AI tooling and formal verification need to move faster than offensive capability. Incidents like this one are the evidence behind that argument.

Market Implications: What It Means for Your Wallet

Regular investors cannot audit code, but they can choose where their assets sit. The practical takeaways are old rules that matter more each year: use hardware wallets for long-term holdings, treat browser extensions and uploaded files — even photos — as potential attack surfaces, and be skeptical of any project whose security story is a single audit from a year ago. The faster exploit development gets, the more valuable the projects that invest in continuous verification become.

There is a market angle too. Security budgets are becoming a competitive moat, and firms that can prove AI-assisted defense — not just AI-assisted attack — may command growing trust from institutions. That theme runs alongside the wider AI-security debate that has swept the industry this year, from fake AI trading bot tutorials draining hundreds of ETH from victims to warnings that AI gives scammers industrial-scale reach.

The Verdict

The OpenAI breach ended harmlessly — a fixed bug, a modest bounty, no stolen code. But it demonstrated in 72 hours what security researchers have predicted for years: the cost of sophisticated attacks is collapsing. For a crypto ecosystem holding hundreds of billions in on-chain value, that is not a hypothetical risk. It is a budget line. The projects that treat AI-era security as infrastructure, rather than an afterthought, are the ones most likely to still be standing when the next exploit race begins.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

11 thoughts on “Claude AI Helped Researchers Breach OpenAI in 72 Hours — and the Crypto Security Math Just Changed”

  1. a HEIC decoder bug chained into employee Codex accounts and then the whole openai monorepo. 72 hours. key management offline looks real good right now

    1. exactly yuki, and if a bug bounty crew did this in 3 days imagine what a state group does in 3 months. hardware wallets staying in the drawer

      1. the codex session token part scares me more than the heap overflow. with AI tooling one phished employee is now effectively the whole perimeter

        1. the session token angle is the real headline. phish one person and the ai agent happily walks the attacker through the repo, no exploit needed

  2. a heap overflow in libheif thru an image upload on a forum. we have been patching that class of bug for 20 years and its still the way in lol

    1. libheif thru imagemagick on a public forum, genuinely the ghost of 2014. every crypto project running a discourse instance should rotate those image pipeline creds today

    2. twenty years of patching and imagemagick still eats untrusted images by default. every crypto forum running it owes their users a config audit tonight

  3. 72 hours from a forum photo to a private monorepo. Bridge auditors and anyone with a Discourse forum should be very nervous reading this.

  4. hacktron did this in 3 days as a demo. the same chain works on any protocol with a support portal, crypto help desks better tighten up before someone less polite tries

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$81,312.00+0.4%ETH$2,637.56+0.4%SOL$111.14-2.1%BNB$762.28-0.1%XRP$1.43+2.0%ADA$0.2306+3.5%DOGE$0.0890+1.5%DOT$1.13-0.5%AVAX$9.76+18.5%LINK$12.52+1.4%UNI$8.65-4.2%ATOM$1.73+2.0%LTC$57.91+1.4%ARB$0.2071-7.5%NEAR$3.55-3.8%FIL$1.02+11.3%SUI$0.8759+8.4%BTC$81,312.00+0.4%ETH$2,637.56+0.4%SOL$111.14-2.1%BNB$762.28-0.1%XRP$1.43+2.0%ADA$0.2306+3.5%DOGE$0.0890+1.5%DOT$1.13-0.5%AVAX$9.76+18.5%LINK$12.52+1.4%UNI$8.65-4.2%ATOM$1.73+2.0%LTC$57.91+1.4%ARB$0.2071-7.5%NEAR$3.55-3.8%FIL$1.02+11.3%SUI$0.8759+8.4%
Scroll to Top