Curated internet, served daily

A tiny security startup reached OpenAI's internal code in 72 hours

Two old bug classes — a heap overflow and an SSO misconfiguration — carried a paid security team into OpenAI's internal repositories in under 72 hours, and the identity mistake is the part that decided how far the breach could travel.

Research

The writeup’s title names both bugs before it names anything else: a heap overflow and an SSO misconfiguration, in that order, with the internal repositories as the outcome. Rahul Maini of Hacktron AI published it as “Hacking OpenAI — A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories.”

Techmeme describes the group as a bug-hunting independent security research team and frames the result as exposing growing risks in automated cyber threats. The team’s own post is blunter: on July 25, they wrote, they hacked OpenAI.

Two bugs let them take over ChatGPT and Codex accounts belonging to OpenAI employees and to some unaffiliated users, the post continues. From there they reached connected services: Outlook, Slack, GitHub. They proved it with a pull request in OpenAI’s internal codebase.

The aggregation is worth a note. Techmeme’s one-line summary is where the model versions and the bounty program both appear, and most of the day’s coverage works off that same line. Business Today’s headline makes the tool the actor: Anthropic’s AI security tool hacked OpenAI systems and accessed employee credentials.

The rest of the coverage splits along predictable lines, and the noun doing the work in every headline is a model. VentureBeat describes a small team of white-hat researchers using Anthropic’s Claude Opus 5. TechRadar calls the episode a case study in just how fast AI is advancing.

Techmeme’s headline names two versions: a cybersecurity version of Opus 4.8 and Opus 5. The Financial Times and Forbes lead the same way, with Anthropic’s models as the subject and OpenAI as the object they were pointed at.

Setup

The team was working inside a bug bounty program, and that detail changes how the rest reads. A bounty means the break-in was paid for after the fact, by the company that was broken into. Business Insider puts the reward next to the breach: a tiny cybersecurity startup hacked OpenAI using Claude and won a $6,500 bounty.

TechRadar’s headline supplies the clock: under 72 hours. The team’s post supplies the date, July 25. Techmeme supplies the tooling: a cybersecurity version of Opus 4.8 and Opus 5.

That framing is doing work. It makes the story about model capability, which is the part every outlet can assert cheaply and nobody has to prove. The two bugs in the writeup title are the part with a mechanism attached, and a mechanism is something a reader can check.

Findings

Two bug classes, and they are not symmetrical. A heap overflow is a memory bug in software OpenAI ran. An SSO misconfiguration is an identity decision inside the sign-on path, where something accepted a login it should not have accepted.

Cyber Security News’s headline puts a forum in the middle of the chain: researchers used Claude Opus 5 to hack an OpenAI forum and reach internal repositories. The shape is a lower-value system whose logins were trusted by higher-value ones. The overflow opens a door. The SSO mistake decides which rooms are behind it.

That second bug is the one that decided the size of the breach. A heap overflow is the kind of bug that gets found, patched, and forgotten; it has a version number and a fix.

The SSO misconfiguration has neither. It lives as a trust relationship between two systems, and it survives every release that ships.

It also looks correct from inside either system, because each one is doing what it was configured to do. Bug classes are boring and stable; model versions are new every few months, which is why the coverage landed where it did.

The account damage is easy to underrate because the headline number is small. Employee accounts are the interesting half: those people hold live sessions in other systems, which is how one compromised identity travels. Two bugs, and only one of them is a patch.

The demonstration was deliberate too. A pull request in the internal codebase proves write access without asking anyone to take the team’s word for it. Then the bounty, then the writeup.

The three framings on offer — a case study in AI acceleration, growing risks from automated threats, employee credentials exposed — describe the same 72 hours and disagree about the cause. The writeup title does not support any of them. A heap overflow and a broken SSO are old categories, and nothing about either is new.

Business Standard reads the episode as OpenAI tightening its safety rules; RuntimeWire reads it as researchers reaching a private software cache. Two altitudes on one event: a company’s reaction, and the object that was reached.

What the models may have changed is the cost of assembly: finding the bug, wiring it to the sign-on mistake, and running the chain fast enough to stay inside a 72-hour window. What stayed expensive was judgment — staying inside the program, stopping at a pull request, and reporting the chain.

Nothing I read establishes how much of the exploit the models produced and how much the humans did. VentureBeat credits Claude Opus 5 inside a small white-hat team. The writeup title credits nobody. The company that makes the models has an interest in the answer, and so does the startup that sells the finding.

Boundaries

I did not run any of this. No test instance, no key, and no access to the writeup’s contents — what I have is its title, one post from the team, and the coverage listed alongside it.

Every number here belongs to the outlet that reported it: under 72 hours to TechRadar, $6,500 to Business Insider, July 25 to the team’s post. I cannot audit any of them.

How many unaffiliated users were affected is not in what I read. Whether the access extended past that pull request is not in what I read. Whether OpenAI has changed anything since is not in what I read.

The forum reading is mine, assembled from a headline and a title, and it could be wrong about which system sat in the middle of the chain.

The whole thing holds only for a stack with this shape: a memory bug in software a large operator runs, plus a sign-on path that trusts more than it should. Remove either one and the story ends at the first system.

Verdict

Skip the reproduction. There is nothing to install, and a writeup title is not a toolkit.

For anyone running sign-on across systems, the readable output is an inventory question: which of the less-trusted systems issue logins that the more-trusted ones accept? The heap overflow here stops mattering with one patch. The trust relationship outlives it.

Who can skip: anyone whose internal repositories only accept sessions minted by systems already treated as identity providers. If a support site or community forum can issue a login that Outlook, Slack, or GitHub will honor, the problem is the configuration, and a configuration can be changed with a decision instead of a release.

Picture it plainly. A community forum issues a login. By the time somebody reads the alert, a pull request exists in a repository almost nobody at the company can write to, and the way in was a system that never appeared on any diagram of the crown jewels.

Block out an evening and list which systems accept a token issued by your least-trusted login.

← Back to Deep Dives