Source · DiggingBeagle record
Hacking OpenAI
Primary narrative and timeline for the Hacktron/OpenAI/Discourse chain. Researcher-authored disclosure; broader connected-service reach is partly theoretical and should be separated from demonstrated actions.
- Published
- Sep 13, 2026
- Accessed
- Sep 18, 2026
- Publisher
- Hacktron
- Source type
- primary technical disclosure
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Primary narrative and timeline for the Hacktron/OpenAI/Discourse chain. Researcher-authored disclosure; broader connected-service reach is partly theoretical and should be separated from demonstrated actions.
Claim-level citations (7)
- supportsHacktron: image processing, SSO and connected development authority: Hacktron reports a July 25 chain from Discourse image processing through an OpenAI SSO flaw into employee ChatGPT/Codex accounts, demonstrated with a harmless internal pull request.
Intro; disclosure timeline; Opus 5 Released
- supportsHacktron: image processing, SSO and connected development authority: The authors identify Opus 4.8 and Opus 5. They say they did not read internal code; access to other connectors was potential rather than demonstrated.
Background; Opus 5 Released
- supportsHacktron: image processing, SSO and connected development authority: The sub-$3,000 token figure covers broader multi-company research. The $6,500 award covered the OpenAI-side finding; the quoted scope clarification excludes testing the Discourse-hosted forum from that bounty.
Costs of finding these vulnerabilities; disclosure timeline item 9
- supportsHacktron: image processing, SSO and connected development authority: The researchers demonstrated internal development authority by having Codex open a harmless pull request, while stating that they did not read internal OpenAI source code.
OpenAI employee account/Codex proof-of-access section
- supportsHacktron: image processing, SSO and connected development authority: OpenAI fixed the account-takeover path on July 25, and Discourse subsequently published a HEIF advisory and image-processing mitigations.
timeline; OpenAI fix confirmation
- supportsHacktron: image processing, SSO and connected development authority: Hacktron says Claude materially accelerated exploit development, including an autonomous loop against a researcher-controlled Discourse instance, but skilled human guidance remained important and the work was not completely autonomous.
sections describing Opus 4.8/Opus 5 exploit development and the /goal loop
- supportsHacktron: image processing, SSO and connected development authority: The disclosure discusses broader potential access through connected services, but it does not establish that those additional services were actually accessed.
discussion of connected applications and stated stopping point
Cite this record
DiggingBeagle. “Hacking OpenAI.” Published Sep 13, 2026 · Accessed Sep 18, 2026. https://diggingbeagle.com/sources/hacking-openai/
Citation guidance