All Articles
4 minUpdated

Inside the HEIF Heist: How One Image Started a Chain Into OpenAI's GitHub

Most RecentTrendingCybersecurity

In September 2026 a story spread that OpenAI had been hacked with one picture. The real attack, which its authors call the HEIF Heist, is more interesting than that. A photo started it, but it only worked because three separate weaknesses lined up. I went through the reports from TechCrunch, VentureBeat, Malwarebytes and eSecurityPlanet to map each link in the chain.

Who was behind it

Hacktron is a small security startup. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini worked on the research for about two months, reported everything through OpenAI's bug bounty program, and published once the fixes were in.

The attack chain, step by step

Five steps from a forum upload to a pull request inside OpenAI's GitHub organization.1HEICupload2libheifmemory bug3Forumcode execution4SSO tokenflaw5Codex + GitHubproof PRTHE HEIF HEIST ATTACK CHAIN
Five steps from a forum upload to a pull request inside OpenAI's GitHub organization.
  1. The upload. OpenAI's community forum runs on Discourse. When someone uploads an iPhone-style HEIC or HEIF photo, Discourse converts it with ImageMagick, which hands the file to the libheif library. VentureBeat describes the bug as a heap buffer overflow in the HEIC decoder.
  2. Code on the forum server. The crafted file let the researchers run code in the forum environment. VentureBeat also points to weak sandboxing around image processing, which is why a decoder bug became a server problem.
  3. The sign-in flaw. You log in to community.openai.com with your OpenAI account. A flaw in how those sign-in tokens were scoped let the forum foothold turn into access to the ChatGPT and Codex accounts of people who had signed in, OpenAI staff included.
  4. Into GitHub. One employee's Codex account had GitHub connected. Through it, the researchers opened a harmless pull request in an internal OpenAI monorepo as proof. VentureBeat reports that the account also had Slack, Outlook, Gmail and Google Drive connected.

How fast everything moved

From model release to public story in under two months.REPLAY · DISCLOSURE TIMELINEJul 24Claude Opus 5 is releasedJul 25Chain works; OpenAI is told and fixes its sideJul 27Discourse ships fixesSep 13Hacktron publishes the HEIF Heist write-upSep 18TechCrunch breaks the story wide
From model release to public story in under two months.

OpenAI narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions. It paid a $6,500 bounty through Bugcrowd. Discourse released patched versions (2026.7.0, 2026.6.1, 2026.5.2 and 2026.1.6, per eSecurityPlanet) and later updated its default base image.

Why the AI part matters

Turning a memory bug into a reliable exploit is slow, specialist work. The team first tried Claude Opus 4.8 and it struggled across several sessions. According to VentureBeat, Claude Opus 5 produced working ARM64 and x86-64 exploits within hours of its release.

One expert quoted by TechCrunch put it bluntly: "For $200 a month, anyone can use these tools and hack into a company like OpenAI." I think that overstates it a little. Humans still found the target, spotted the sign-in weakness and chained the steps. What changed is the cost of the hardest step, and defenders should plan around that.

What developers should take from this

What developers and forum admins can do this week.Patch and rebuild DiscourseProcess uploads in a sandboxScope SSO tokens per appLimit what AI agents can reachWatch GitHub audit logs
What developers and forum admins can do this week.

Most of these are old advice. Treat every uploaded file as hostile and decode it somewhere that cannot reach anything important. Give each SSO token only the scope that one app needs, because a forum login should never be able to act as a full ChatGPT session. The newer lesson is about AI coding agents: an agent account connected to GitHub, Slack and mail is a very valuable key, so connect only what the agent needs and review its access regularly.

A more accurate headline

"Researchers chained a malicious image bug with an OpenAI sign-in flaw to reach an internal repository." It is longer and less dramatic, but it tells you where the real weakness was.

I also wrote a shorter myth-versus-fact version on my blog.

Sources