A 3-person team at security startup Hacktron AI chained 2 vulnerabilities that began with a HEIF upload to OpenAI’s community forum and ended with logged-in access to employee accounts for ChatGPT and Codex. The exploit chain was completed in under 72 hours.
The work involved Claude Opus 5, according to the report’s headline. OpenAI paid Hacktron AI $6,500 for the security report.
How the chain began
The initial entry point was community.openai.com, OpenAI’s community forum. The site runs on Discourse, a forum platform that decodes uploaded HEIC and HEIF s.
Hacktron’s researchers linked 2 vulnerabilities rather than relying on a single flaw. The supplied account identifies the sequence from an upload on the forum to logged-in access to OpenAI employee accounts.
The affected accounts included access to ChatGPT and Codex. The material does not establish any further activity after that access was obtained.
Why the finding matters
The case connects a public-facing community forum with access to employee services through a chained exploit. It also places Claude Opus 5 in the researchers’ workflow, while the technical entry point involved HEIF processing on a Discourse-based forum.
Hacktron AI’s team consisted of 3 people. Their work moved from the initial forum-based entry point to the reported account access in less than 72 hours, before OpenAI paid $6,500 for the report.
Key verified details
- Hacktron AI is a security startup.
- The research team had 3 members.
- The chain involved 2 vulnerabilities.
- The first entry point was a HEIF upload to community.openai.com.
- The forum runs on Discourse and decodes HEIC and HEIF s.
- The reported access reached logged-in OpenAI employee ChatGPT and Codex accounts.
- The chain came together in under 72 hours.
- OpenAI paid $6,500 for the report.
Conclusion
Hacktron AI reported a 2-vulnerability chain that moved from a HEIF upload on OpenAI’s Discourse-based community forum to logged-in employee ChatGPT and Codex accounts. The team completed the work in under 72 hours and received $6,500 from OpenAI for the report.
Frequently Asked Questions
Q. Who found the OpenAI account vulnerability?
Hacktron AI, a security startup with a 3-person team, reported the chain.
Q. Where did the exploit chain start?
It started with a HEIF upload to community.openai.com, OpenAI’s community forum.
Q. Which OpenAI accounts were reached?
The reported access reached logged-in employee accounts for ChatGPT and Codex.
Q. How many vulnerabilities were chained?
The team linked 2 vulnerabilities in the reported sequence.
Q. How quickly was the exploit chain assembled?
The full chain came together in under 72 hours.
Q. How much did OpenAI pay for the report?
OpenAI paid Hacktron AI $6,500 for the report.
Q. Which AI model was used in the research?
The report identifies Claude Opus 5 as part of the work.














