Hacktron used Claude Opus 5 to reach OpenAI’s internal GitHub in <72h
White-hat firm Hacktron chained a Discourse/libheif image bug with an OpenAI SSO flaw, then used an employee’s Codex session to open a harmless PR in an internal repo—under 72 hours end to end. Claude Opus 5 built the working exploit overnight after Opus 4.8 failed; OpenAI patched in ~14 hours and paid a $6,500 bounty.
