← Back to Daily Briefing (#TokenReplay)

OpenAI Account Compromise via Claude Opus 5 and Help Forum Vulnerability

Published September 21, 2026

In September 2026, researchers chained a stored XSS/CSRF flaw in OpenAI’s help forum with a token‑replay weakness in its password‑reset flow, using Anthropic’s Claude Opus 5 to automate exploit generation and session hijacking. The attack yielded control of seven employee accounts, granting read‑only access to private source repositories and demonstrating a feasible path to model‑weight exfiltration or backdoor insertion within ~45 minutes.

  • Introduction/Overview
  • Proof‑of‑concept conducted by Hacktron Security Research Team under responsible disclosure.
  • Targeted OpenAI employee accounts via forum‑based session theft and reset‑token abuse.
  • Claude Opus 5 LLM employed to craft convincing forum posts and adaptive payloads.
  • Findings disclosed to OpenAI prior to public reporting; linked to broader BragJack extension hijack campaign.

  • Vulnerability Mechanics/Deep Dive

  • Stored XSS/CSRF in forum software allowed injection of
    NVIDIA's Acquisition of Hugging Face nvidianews.nvidia.com • 23h

LINK COPIED TO CLIPBOARD