Hacking OpenAI
Hacktron AI ● Covered by 7 sources
Hacktron reported a security exploit chain that first compromised OpenAI employee ChatGPT/Codex accounts and then enabled access to OpenAI internal repositories via an OpenAI SSO identity flaw and a libheif heap overflow in the company’s forum image uploads. The exploit timeline from initial discovery to gaining internal repository access took less than 72 hours, and OpenAI paid Hacktron a $6,500 bounty after they coordinated patching. The incident resulted in patched SSO and forum/decoder components (with self-hosted Discourse installations instructed to rebuild to remove vulnerable libheif via Docker/launcher rebuilds rather than a web-only update).
Why it matters
Researchers chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts in July. The accounts could access internal OpenAI repositories and potentially many other connectors, and the post lays out a full timeline of how disclosure unfolded.
Related stories
Now we have a timeline of the OpenAI accidental attack against Hugging Face
Simon Willison’s Weblog · 1 month ago ·
44
The inside story on why OpenAI agents hacked Hugging Face
MIT Technology Review · 3 weeks ago ·
32
What Happened: OpenAI and HuggingFace
Zvi (Don't Worry About the Vase) · 1 month ago ·
47