Featured image of post Security Researchers Use Claude Opus to Help Hack into OpenAI Employee Accounts: The HEIF Heist

Security Researchers Use Claude Opus to Help Hack into OpenAI Employee Accounts: The HEIF Heist

Three researchers used Claude Opus to exploit a HEIF flaw in Discourse, gaining access to OpenAI employee accounts.

The Core Event: Claude Opus Assists in 72-Hour OpenAI Employee Account Breach

The Core Event: Claude Opus Assists in 72-Hour OpenAI Employee Account Breach
The Core Event: Claude Opus Assists in 72-Hour OpenAI Employee Account Breach|News screenshot

Security researchers at Hacktron compromised OpenAI employee accounts within 72 hours—assisted by Anthropic’s Claude Opus 5. The attack targeted OpenAI’s third-party community platform, Discourse, exploiting a flaw in its HEIF image processing logic.

  • Version & Timeline: Claude Opus 5 launched on July 24 evening; by the next day at 10 AM, RCE on Discourse Cloud was achieved
  • Attack Path: Leveraged Discourse’s HEIF image processing vulnerability via a malformed image file
  • Remediation: Vulnerabilities reported to Discourse and OpenAI have since been patched; OpenAI paid $6,500 as a bounty
  • Cost: Under $3,000 in Claude tokens for the entire campaign

Unexpected contrast: Among targets including Meta, Slack, and GitHub Enterprise, only Shopify detected the attack, revealing unusually high stealth for this exploit chain.

Technical Deep Dive: How HEIF Heist Works

Hacktron named the campaign ‘HEIF Heist’. HEIF (High Efficiency Image Format) is a modern image container format widely used in mobile and web to reduce file sizes. The team crafted a malformed HEIF file and uploaded it through Discourse’s image upload interface; during server-side parsing, the defect triggered remote code execution.

The chain consists of three steps:

  1. Upload malicious HEIF file through Discourse forum interface
  2. Server-side image parser triggers RCE during parsing
  3. Attacker obtains session/cookie tokens, impersonating authenticated users

Using these footholds, researchers submitted a Pull Request from an employee’s Codex account, proving access to OpenAI’s internal ‘Monorepo’ repository. Crucially, they halted before reading internal algorithmic secrets, using the PR alone as proof-of-concept.

Expansion Scope: Reusability of the Attack Framework

Expansion Scope: Reusability of the Attack Framework
Expansion Scope: Reusability of the Attack Framework|News screenshot

Hacktron stated the HEIF Heist framework required only ‘one or two days’ to adapt per target. Reported affected systems include:

  • OpenAI
  • Slack
  • Meta
  • GitHub Enterprise
  • Rails (Ruby on Rails)
  • Next.js
  • ImageMagick

Note:‘Ghostty’, a terminal emulator with image preview, was not involved—it appears only in unrelated discussions and was omitted from this report per source constraints.

Claude Opus 5 served as an attack multiplier, aiding in payload construction, PoC scripting, and reverse-engineering of Discourse responses.

Cost vs. Reward Breakdown

ItemCost/ReturnDetail
Claude Tokens< $3,000Opus 5 combined
Bounty Received$6,500Paid by OpenAI
Total Time≤72 hoursFrom Opus 5 release to working exploit

Mitigation: Risks and Recommendations

Mitigation: Risks and Recommendations
Mitigation: Risks and Recommendations|News screenshot

  • Enterprises: Run image uploads through sandboxed analysis; patch libheif, ImageMagick and similar image parsers—all core Discourse image dependencies. Segment Discourse instances from internal services.
  • Developers: Avoid uploading unvetted images to public forums; when using Claude for file generation, never deploy suspect payloads to production endpoints.

In Closing

This breach highlights how performance-oriented formats like HEIF can become attack surfaces when parser libraries are outdated. As the WSJ quoted Hacktron’s CTO: ‘I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.’ The incident reminds us that high-impact vulnerabilities no longer require elite resources—just time, tooling, and a clever chain.