Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • So it went:

    > HEIF upload → libheif overflow → code execution on the forum → over-permissioned SSO tokens → employee ChatGPT/Codex account → connected GitHub → pull request in openai/openai

    Server side bounties aren't that profitable though:

    > A two-month project, under $3,000 in model tokens .... OpenAI paid Hacktron a $6,500 bounty for the account-takeover flaw on its side.

    The ideal hacker workflow would be to gain access to an account or system with model access which you can use for further hacks.

Explore Birbla archives

Claude couldn't hack OpenAI. Then Anthropic shipped Opus 5 · Birbla