Summary
Wes Roth breaks down how the cybersecurity firm Hacktron used Anthropic’s Claude models, specifically Opus 4.8 and later Opus 5, to find and exploit a critical vulnerability in OpenAI’s help forum software, Discourse. The flaw stemmed from ImageMagick, the same image-processing library famously lampooned in an old XKCD comic, and ultimately allowed access to OpenAI employee ChatGPT and Codex accounts as well as parts of its internal code repository.
The video walks through the exploit chain in detail: a heap buffer overflow vulnerability that Opus 4.8 identified but couldn’t fully weaponize, followed by Opus 5 achieving remote code execution within hours of its release on July 24. OpenAI reportedly paid a $6,500 bug bounty for the disclosure.
Roth uses the incident to make a broader point about how frontier AI models are changing offensive security research, referencing the earlier Hugging Face hack as part of a pattern where widely-used dependencies create systemic exposure. The video is useful for anyone tracking how AI models like Claude are reshaping vulnerability discovery and exploit development, and what that means for companies like OpenAI as their own infrastructure becomes a target.
📺 Source: Wes Roth · Published September 19, 2026
🏷️ Format: News Analysis







