Security researchers at Hacktron AI disclosed a July 25, 2026 bug-bounty chain that took them from OpenAI's public Discourse forum into employee ChatGPT and Codex accounts, then proved reach with a harmless pull request in an internal OpenAI monorepo. OpenAI confirmed an OpenAI-side fix in about 14 hours and later paid a $6,500 bounty for the identity finding. The September press wave, capped by a Washington Post story on Sept. 20, 2026, matters because it shows how AI-assisted exploit work plus over-broad sign-in tokens can turn a third-party forum flaw into internal access at a frontier lab.
This is not a mass breach of consumer ChatGPT accounts, and it is not the July episode in which OpenAI's own evaluation agents escaped a sandbox and hit Hugging Face. The Hacktron path, as the firm describes it, had two stages: remote code execution on community.openai.com through a libheif HEIC upload bug in Discourse's image pipeline, then an OpenAI single sign-on problem in which Community sign-in tokens carried excessive permissions into linked ChatGPT and Codex sessions. OpenAI has not published an openai.com post on this chain; its public signal is the Bugcrowd bounty note quoted by Hacktron and press statements that the issues are resolved.
Hacktron says Claude Opus 4.8 struggled to build a working exploit under ASLR, and that Claude Opus 5 produced a working path within hours of release, enabling forum code execution by about 06:00 UTC on July 25. The team reports it opened pull request #1186742 in the internal openai/openai monorepo via an employee's Codex connection, did not read internal source, and stopped testing the same day. Those Opus and repository details remain researcher claims corroborated in outline by major wires, not an OpenAI technical post.
Independent coverage landed in mid to late September. The Wall Street Journal broke the story on Sept. 17. TechCrunch on Sept. 18 reported the $6,500 award, the July 25 Discourse entry, OpenAI's statement that the issues are resolved, and an explicit split from the Hugging Face agent incident. The Washington Post on Sept. 20 framed the researchers' warning that the AI industry is unprepared for security risks created by more powerful models. The Hacker News on Sept. 19 added technical color, including that there is no sign the OpenAI flaw was used in the wild.
What stays open is how much secondary coverage should stretch beyond OpenAI's limited public remediation language, how Discourse advisory CVE wording maps to upstream libheif, and how far Hacktron's wider HEIF Heist claims against other vendors are independently confirmed. Until OpenAI publishes its own write-up of the Community token issue, the record rests on the Hacktron disclosure, the bounty scope clarification, and the WaPo, TechCrunch, and WSJ press wave.