White Hat Hacker Gains Access to OpenAI Internal Code, Earns $6,500 Reward

White hat security research team Hacktron AI revealed they accessed OpenAI employee accounts and an internal code repository using Claude. The team reported the vulnerability to OpenAI in exchange for a $6,500 (approximately 9.02 million KRW) reward.
According to TechCrunch, three Hacktron AI researchers identified a libheif vulnerability used in Discourse's image processing on July 25, which enabled remote code execution. They then exploited an OpenAI single sign-on (SSO) configuration error to access employee ChatGPT and Codex accounts, creating a pull request via GitHub-connected Codex accounts to demonstrate their access.
OpenAI stated it has fixed the account hijacking path and revoked affected tokens and sessions. The research team explained they initially failed to write an exploit using Claude Opus 4.8 but succeeded with Claude Opus 5 to complete the vulnerability attack code.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 오픈AI 내부 코드 접근한 화이트햇, 포상금 6500달러