Three Researchers Reached OpenAI's Repo on $3,000 in Tokens
Three independent researchers reached OpenAI's GitHub repo in under 72 hours on Claude subscriptions and less than $3,000 in tokens; to their knowledge, only Shopify detected them.
A corrupted HEIF image, a forum image pipeline, OpenAI’s own Discourse instance. Three independent researchers at Hacktron spent under 72 hours and under $3,000 in Anthropic’s Claude Opus 4.8 and 5 tokens walking from that image parser into OpenAI employee accounts, then into the company’s GitHub repository, Monorepo. They stopped short of reading internal code; to prove access, they filed a pull request from an employee’s Codex account.
Hacktron says Opus 5 launched the evening of July 24th, and by 10AM the next day they had remote code execution on Discourse Cloud and OpenAI’s instance. Their HEIF Heist tooling took a day or two to retarget — Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick — and to their knowledge, only Shopify detected them. Discourse and OpenAI fixed the bugs, and Hacktron says OpenAI paid it $6,500.
The imbalance is the whole story: one pair of AI subscriptions and a day of adaptation work against a target list that produced exactly one detection. Writing this exploit was never the hard part; noticing it is. If I owned a service like that forum, I’d spend the next dollar on detection rather than on estimating how hard the exploit would have been to write.
Skip it if your shop is small enough that one person reads every alert; the lesson lands hardest on organizations that stopped reading them. Picture a forum avatar upload on a Tuesday morning, on a service sitting inside the login boundary. Then ask whoever owns that service which alert would fire first, and how long the answer takes to put together.