← AI news

YouTube · Wes Roth ·

OpenAI Hacked Within 72 Hours: Access to ChatGPT, Codex and Monorepo

Wes Roth reported that a hacking group gained access to OpenAI's ChatGPT and Codex accounts, as well as its internal monorepo, in less than 72 hours. The attack leveraged ImageMagick and Opus 5 heap buffer overflow vulnerabilities, enabling rapid adaptation of AI‑based autonomous agents.

Wes Roth informed that a hacking group gained access to OpenAI's ChatGPT and Codex accounts, as well as its internal monorepo, in less than 72 hours. The attackers performed remote code execution using the ImageMagick vulnerability and an Opus 5 heap buffer overflow, modifying the codebase and exploiting the SSO vulnerability.

During the hack, they used Google's Single Sign‑On system, so no password was required. OpenAI offered a $6,500 USD reward for the investigation. The monorepo may have contained backend code, training materials, and security systems.

The attackers also exploited a vulnerability in an image‑processing library (ImageMagick) to gain access to the servers, then advanced the incident with a heap buffer overflow exploit discovered with the Opus 4.8 model. After the release of Opus 5, it became possible to breach the Discourse forum.

Wes Roth emphasized that AI‑based autonomous agents quickly adapt to corporate environments, can perform privilege escalation and lateral movement, significantly increasing potential damage.

Source: https://www.youtube.com/watch?v=iQGLI14p88Q