Wednesday, Sep 23, 2026
1 Researchers Hack OpenAI Using Claude Opus 5 to Find Decoder FlawPVT:OPAIPVT:ANTH 🔒 Cybersecurity Sep 23, 5:00 PM EDT 7/4
A security team compromised an OpenAI public help forum server by identifying a memory corruption bug in a widely used image decoding tool. Three researchers spent 2 months and under $3,000 in AI tokens utilizing Anthropic's Claude and OpenAI's Codex to uncover the vulnerability, which they nicknamed "HEIF Heist." The exploit enables remote code execution and the theft of sensitive data, leaving platforms including Meta, Amazon Web Services, and GitHub Enterprise at risk. OpenAI paid the group $6,500 after the discovery and patched its systems in 14 hours.
The vulnerability persisted because a fix applied to the software upstream was never assigned a CVE identifier, leaving downstream users unaware of the security risk. The researchers found that Claude Opus 5 cracked the flaw within hours of its release, whereas older AI models failed to identify it. Other services, including the internet forum Discourse, remain vulnerable if they use the affected image library.