NEWS

OpenAI Has Accounts Hijacked From an Image Sent to the Forum

OpenAI had employee accounts on ChatGPT hijacked by three researchers. The trio is made up of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini.

OpenAI Has Accounts Hijacked From an Image Sent to the Forum
Image: Redação iMasters

OpenAI had employee accounts on ChatGPT hijacked by three security researchers. The trio is made up of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, from Hacktron AI. To structure the attack, they used Claude models, from rival Anthropic.

The operation took less than 72 hours. That window covers everything from the first vulnerable point to a change proposal submitted to the company's internal monorepository.

After the alert, the fix shipped in about 14 hours. In addition, the company paid a US$6,500 bounty to the researchers.

OpenAI Saw the Breach Emerge in a Poorly Watched Spot

The entry point was the public help forum. That service runs on the Discourse platform.

The researchers noticed a detail in image uploads. HEIC and HEIF files went through an outdated image-processing library.

That weakness allowed remote command execution. As a result, the group took control of the forum server.

Notice the type of component involved. A small image library, maintained by very few people, underpinned a service run by one of the largest AI companies.

Single Sign-On Turned a Forum Into a Master Key

Here the problem gained scale. In addition, the company unified access to the forum with its other products through single sign-on.

So, whoever controlled the community server could take over user and employee accounts. Worse still, victims didn't even need to click on anything.

The researchers described the theoretical reach. Since many people connect services to ChatGPT and Codex, the access could extend to GitHub, Slack, and email.

To prove the point carefully, the group used an employee's account. With it, they opened a harmless change request in the internal monorepository. Right after that, they stopped everything and alerted the security team.

Claude Opus 4.8 Found the Flaw and Opus 5 Closed the Code

In addition, the division of labor between the models stands out. Claude Opus 4.8 found the flaw and put together a preliminary version of the test.

Then, Claude Opus 5 delivered the final code. According to the researchers, this took just a few hours.

The case was part of a broader survey called HEIF Heist. However, over two months of testing against large tech companies, the trio spent less than US$3,000 on AI processing.

Therefore, the cost of finding this kind of breach has plummeted.

OpenAI Rewarded the Discovery and Marked the Scope Limit

The company added a caveat in the statement sent to the researchers. Tests against the forum were outside the original scope of the bounty program.

Even so, the severity of the internal flaw was acknowledged. According to the message, the bounty refers to what was found on the company's own side.

The Discourse maintainers also reacted quickly. They published an official alert recommending that image processing be isolated in installations.

The End of Security Through Complexity

Hacktron AI's report brings the case's most important argument. For a long time, turning a public flaw into a working attack required rare knowledge and a lot of time.

Now, according to the researchers, AI converts that scarce expertise into processing power. As a result, months of work fit into a few days.

This point changes the risk calculation for any team. Old, low-visibility dependencies start being exploited quickly.

What to Review in Your Environment After This Case

Start with file-processing libraries. Images, PDFs, and videos uploaded by users go through code that rarely gets attention.

Then, isolate that processing. Run the conversion in a separate container, without network access and with minimal privileges.

Also review the scope of single sign-on. Peripheral services, such as forums and help centers, deserve sessions separate from critical systems.

In addition, limit the reach of integrations. However, tokens connected to GitHub, Slack, and email need minimal scope and short expiration.

Finally, monitor transitive dependencies. Software composition analysis tools flag vulnerable versions before the attacker gets there.

What to Watch Going Forward

Watch for new HEIF Heist reports involving other companies. Also follow the adoption of Discourse's recommendations across public installations.

In the meantime, it's worth asking your team an honest question. If a trio spending less than US$3,000 on AI reached OpenAI's internal repository, which peripheral service opens the way to yours?

Follow our profile on Instagram!

Translated from the Brazilian Portuguese original · Read the original

More from Redação iMasters
View profile →