Three independent security researchers used Anthropic’s Claude to break into OpenAI employee accounts, chaining two flaws in Discourse, the forum software behind OpenAI’s community help site, into a full OpenAI account takeover of ChatGPT and Codex logins. The team, working as Hacktron and made up of Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, then used that access to reach one of OpenAI’s internal GitHub repositories.
Anthropic had given the three researchers access to a Claude tool built for security professionals and paid them for the work, part of a program aimed at catching this kind of flaw before criminals do. The entire chain, from the first Discourse bug to touching OpenAI’s internal repository, took under 72 hours. OpenAI’s bug bounty programme on Bugcrowd paid the trio $6,500 for the disclosure.
How the OpenAI account takeover worked
OpenAI runs its public help forum, community.openai.com, on Discourse, third-party software also used by thousands of other sites. Hacktron found two separate flaws in that software and chained them to hijack the login sessions of multiple OpenAI employees on the forum. Because ChatGPT and Codex both let users connect external services to their accounts, a forum session turned out to be enough to pull in live ChatGPT and Codex sessions as well.
The researchers used Claude Opus 4.8 and the newer Opus 5 to develop and refine the exploit chain, and Opus 5 got past a common security check that Opus 4.8 could not. That gap between the two models showed up during a live intrusion, not on an Anthropic benchmark chart, which is the part worth sitting with: a percentage-point uplift on a capability leaderboard is a claim, a model clearing a defence its predecessor couldn’t is a result.
What the forged pull request proved
Rather than pull data out of OpenAI’s codebase, the researchers used a hijacked Codex account to open a pull request against OpenAI’s internal repository, reportedly called Monorepo and said to hold the company’s algorithmic secrets. The pull request itself was harmless. Its only purpose was to prove an outside party could reach the repository at all, not to extract or alter anything inside it.
The blast radius was wider than the first reports suggested
Early framing of the story described a single OpenAI employee’s ChatGPT account being read. The Register‘s writeup carries the researchers’ own account of the exposure, which was considerably larger: “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over.” That is not one account, it is every account with forum access, for as long as the Discourse flaws went unpatched.
It is the same underlying failure mode as the authentication bypass zero-day teqpost covered on Cisco’s ISE platform: a login boundary meant to isolate one system turns out to be shared with others, and the shared boundary is where the real exposure sits.
What to watch next: the Discourse flaws were already fixed by the time Hacktron published its findings, patched roughly two months before the report went public. The open question is whether OpenAI, or any lab running similar account-linking between a help forum and its core products, audits which third-party services can pull a live session into ChatGPT or Codex, since that linking is what turned a forum bug into a path toward an internal repository.








