The Core Event: Claude Opus Assists in 72-Hour OpenAI Employee Account Breach

Security researchers at Hacktron compromised OpenAI employee accounts within 72 hours—assisted by Anthropic’s Claude Opus 5. The attack targeted OpenAI’s third-party community platform, Discourse, exploiting a flaw in its HEIF image processing logic.
- Version & Timeline: Claude Opus 5 launched on July 24 evening; by the next day at 10 AM, RCE on Discourse Cloud was achieved
- Attack Path: Leveraged Discourse’s HEIF image processing vulnerability via a malformed image file
- Remediation: Vulnerabilities reported to Discourse and OpenAI have since been patched; OpenAI paid $6,500 as a bounty
- Cost: Under $3,000 in Claude tokens for the entire campaign
Unexpected contrast: Among targets including Meta, Slack, and GitHub Enterprise, only Shopify detected the attack, revealing unusually high stealth for this exploit chain.
Technical Deep Dive: How HEIF Heist Works
Hacktron named the campaign ‘HEIF Heist’. HEIF (High Efficiency Image Format) is a modern image container format widely used in mobile and web to reduce file sizes. The team crafted a malformed HEIF file and uploaded it through Discourse’s image upload interface; during server-side parsing, the defect triggered remote code execution.
The chain consists of three steps:
- Upload malicious HEIF file through Discourse forum interface
- Server-side image parser triggers RCE during parsing
- Attacker obtains session/cookie tokens, impersonating authenticated users
Using these footholds, researchers submitted a Pull Request from an employee’s Codex account, proving access to OpenAI’s internal ‘Monorepo’ repository. Crucially, they halted before reading internal algorithmic secrets, using the PR alone as proof-of-concept.
Expansion Scope: Reusability of the Attack Framework

Hacktron stated the HEIF Heist framework required only ‘one or two days’ to adapt per target. Reported affected systems include:
- OpenAI
- Slack
- Meta
- GitHub Enterprise
- Rails (Ruby on Rails)
- Next.js
- ImageMagick
Note:‘Ghostty’, a terminal emulator with image preview, was not involved—it appears only in unrelated discussions and was omitted from this report per source constraints.
Claude Opus 5 served as an attack multiplier, aiding in payload construction, PoC scripting, and reverse-engineering of Discourse responses.
Cost vs. Reward Breakdown
| Item | Cost/Return | Detail |
|---|---|---|
| Claude Tokens | < $3,000 | Opus 5 combined |
| Bounty Received | $6,500 | Paid by OpenAI |
| Total Time | ≤72 hours | From Opus 5 release to working exploit |
Mitigation: Risks and Recommendations

- Enterprises: Run image uploads through sandboxed analysis; patch libheif, ImageMagick and similar image parsers—all core Discourse image dependencies. Segment Discourse instances from internal services.
- Developers: Avoid uploading unvetted images to public forums; when using Claude for file generation, never deploy suspect payloads to production endpoints.
In Closing
This breach highlights how performance-oriented formats like HEIF can become attack surfaces when parser libraries are outdated. As the WSJ quoted Hacktron’s CTO: ‘I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.’ The incident reminds us that high-impact vulnerabilities no longer require elite resources—just time, tooling, and a clever chain.
