Media & Culture

Three Guys With AI Broke Into OpenAI in Under 72 Hours

If three people with a chatbot can do this, your company's data may be next.

Deep Dive

A small research team called Hacktron — just three people — managed to break into OpenAI's employee accounts in less than three days, according to The Wall Street Journal. Their secret weapon wasn't a giant server farm or a government budget. It was a subscription to Claude, the AI made by OpenAI's rival Anthropic, which they used to write and test the attack for them.

The way in was surprisingly ordinary. OpenAI's community forum runs on Discourse, a popular piece of off-the-shelf forum software used by thousands of companies. Hacktron found a flaw in how that software handled HEIF images — the photo format iPhones use by default. A deliberately corrupted image let them run their own commands on the server. From there, they reached OpenAI's GitHub code repository, nicknamed "Monorepo," which reportedly holds the company's algorithmic secrets. They didn't dig into the code itself, but proved they could by sending a change request from an employee's account.

What makes this alarming isn't one broken website. It's the price tag and the speed. Hacktron says adapting the same trick to other targets — including Slack, Meta, GitHub, and Shopify — took only one or two days each, and the whole campaign cost under $3,000 in AI usage fees. Of all those companies, only Shopify noticed. As Hacktron's CTO put it, "We're just three guys with Claude and Codex subscriptions."

The good news: the flaws were reported and fixed, and OpenAI paid a $6,500 bug bounty — a reward for finding security holes. The uncomfortable lesson is that the skills needed to break into a major tech company just got much cheaper. If a three-person team can do this in a weekend, so can criminals, and the software guarding your data may be the same free forum tool used everywhere.

Key Points
  • Three people with AI subscriptions — not a government hacking team — got into OpenAI's internal systems in under three days.
  • They spent less than $3,000 on AI usage fees, and OpenAI paid them $6,500 for reporting the flaw.
  • The same technique also worked on Slack, Meta, GitHub and others — only Shopify spotted it.

Why It Matters

AI is slashing the cost of breaking into companies — the software guarding your data may already be behind.

📬 Get the top 10 AI stories daily