02

Three researchers used Claude to reach OpenAI's internal GitHub in 72 hours for a $6,500 bounty

verifiedDeveloperLegal

Friday, September 18, 2026

Confidence

High · — WSJ primary + Forbes, Invezz, Tech Portal corroborating; downstream impact of source-code access unknown

Evidence

bug-bounty disclosure + WSJ reporting + Hacktron writeup

Hacktron AI ran Claude in an autonomous loop against an OpenAI-side Discourse flaw, chained SSO tokens into an employee's Codex, and opened a pull request inside the internal openai/openai monorepo.
  • Under $3,000 in tokens, $6,500 bounty; WSJ broke it, OpenAI patched in ~14 hours.
  • The team used a Claude version restricted to qualified cybersecurity practitioners.

Sources

Apply this today

The hands-on layer the brief points to: a workflow you can run, a tool to test, and today’s 60-second video.

▶ Watch today’s 60-second brief →