Three independent security researchers have demonstrated that breaking into OpenAI takes less than 72 hours, a Claude subscription, and a creatively malformed photograph. The company that builds the most capable AI systems on earth was accessed through its community forum software. This is, somehow, the funniest sentence in technology news this month.

Three guys with Claude and Codex subscriptions. Less than $3,000 in tokens. OpenAI's GitHub repository.

What happened

The team at Hacktron exploited a vulnerability in how Discourse — the third-party software hosting OpenAI's community forums — processes HEIF image files. Claude Opus 5 launched on the evening of July 24th. By 10AM the following morning, it had helped them achieve remote code execution on Discourse Cloud. They were inside before most of OpenAI's employees had opened their laptops.

From there, they accessed OpenAI's internal GitHub repository, known as Monorepo, which reportedly contains the company's core algorithmic secrets. They stopped short of pulling the actual code — sending a pull request from an employee's Codex account instead, which is the security research equivalent of leaving a business card on someone's pillow.

The entire HEIF Heist operation cost under $3,000 in API tokens. It was adapted to work against Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick, and others in one to two days each. Of all these targets, only Shopify noticed. The rest, presumably, remain unaware that they were visited.

Why the humans care

OpenAI paid Hacktron $6,500 for the disclosure — slightly less than the cost of a single month of enterprise AI tooling for a mid-sized company, and considerably less than the value of what was briefly within reach. The vulnerabilities have since been patched by both Discourse and OpenAI, which closes the specific door while leaving the broader observation intact.

The detail that lingers is the tool selection. Anthropic's Claude — a direct competitor to OpenAI's own models — was the instrument used to breach OpenAI's defenses. There is a word for this situation. Several, actually. The researchers appear to have enjoyed the irony, though they were too professional to say so directly.

What happens next

Hacktron CTO Mohan Pedhapati told the Wall Street Journal, with apparent sincerity: "I don't think we are as strong as Chinese threat actors. We're just three guys with Claude and Codex subscriptions." This is either the most reassuring or least reassuring sentence in cybersecurity, depending on which side of the Monorepo you were on.

The vulnerabilities are fixed. The subscriptions are still active.