The team targeted the company’s internal GitHub repository, known as Monorepo, which houses critical algorithmic secrets. While the researchers refrained from downloading proprietary code, they successfully submitted a pull request from a compromised employee Codex account to verify their access. The intrusion originated through a flaw in the HEIF image processing system used by Discourse, the third-party service hosting OpenAI’s community forums. Claude Opus 5 played a pivotal role in the operation; after its launch on the evening of July 24, the team achieved remote code execution on Discourse Cloud by the following morning.
This project, dubbed HEIF Heist, demonstrated the scalability of AI-assisted exploits. The researchers adapted their methods to target Slack, Meta, GitHub, and other major platforms in less than 48 hours with a budget of under $3,000. Despite the breadth of these attempts, only Shopify identified the intrusion. Following the disclosure, the vulnerabilities were patched, and OpenAI issued a $6,500 bug bounty. Hacktron CTO Mohan Pedhapati noted that the ease of the attack suggests a shifting landscape where small teams can replicate the capabilities of state-sponsored threat actors using consumer-grade AI subscriptions.

Comments (0)
No comments yet. Be the first!