AI-Assisted Researchers Chained Two Flaws to Access OpenAI Staff Accounts
Three researchers at security firm Hacktron used Anthropic's Claude Opus 5 AI model to chain together two separate flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, eventually reaching an internal code repository. The attack path started with a bug in the software running OpenAI's public help forum and moved through a weakness in OpenAI's own single sign-on (SSO) login system, which staff also use to access other internal tools.
This was authorised security research rather than a malicious attack. The team reported the issue to OpenAI, demonstrated access with a harmless code submission, and stopped there. Internal access was achieved in under 72 hours, and OpenAI confirmed a fix within roughly 14 hours of the report, later paying a $6,500 bounty for the OpenAI-side finding.
The core issue was identity-related rather than a forum software flaw: because OpenAI's forum used the same SSO as ChatGPT and Codex, compromising the forum let the researchers hijack connected staff accounts without any action from the victims. Since staff often link these accounts to other tools such as GitHub, Slack, and email, the researchers noted the access could theoretically have extended much further, though they did not test this.