We Hacked OpenAI. Here's what didn't fit in 90 seconds: → OpenAI was only one target. It was part of a bigger research project we call the HEIF Heist → 2 months, 3 researchers, under $3,000 in AI tokens → The bug we used had already been fixed upstream. It just never got a CVE, so it never got patched downstream → The older Claude model got stuck. Claude Opus 5 cracked it within hours of release → OpenAI paid us $6,500 for the finding :). The scary part isn't OpenAI. They fixed it in 14 hours. It's every other company running the same image software, still unpatched, with no CVE telling them to care. Harsh, Mohan and Rahul wrote up everything. Visit -
Researchers used Claude Opus 5 to crack a HEIF-related bug that stumped an older model, netting a bounty from OpenAI; the underlying flaw likely remains unpatched in other companies running the same image library since it was never assigned a CVE.
Checking sign-in…
Loading comments…