Hacktron used Claude Opus 5 to chain forum flaws into OpenAI staff accounts
Hacktron researchers used Claude Opus 5 to help chain a Discourse/libheif image bug into OpenAI staff ChatGPT and Codex accounts, then opened a harmless demo PR in an internal repo. OpenAI patched within about 14 hours and paid a $6,500 bounty on Sept 1; there is no sign the chain was abused in the wild.