🧑💻 AI Hacking: The $6,500 Hack

It took less than 72 hours to reach OpenAI’s internal code repositories.
The reward for finding the hole?
$6,500.
Security researchers at Hacktron say they chained together two vulnerabilities that allowed them to compromise OpenAI employee ChatGPT accounts and reach connected services, including an employee’s Codex access to OpenAI’s internal GitHub repositories.
To prove the access without reading internal code, they instructed the employee’s Codex account to create a harmless pull request inside OpenAI’s internal monorepo, then stopped testing and reported the issue.
OpenAI confirmed a fix roughly 14 hours after the initial report, according to Hacktron’s timeline. The eventual $6,500 bounty covered the OpenAI-side vulnerability rather than necessarily valuing the entire exploit chain.
That would already be a remarkable cybersecurity story.
But it isn’t really the story.
AI helped them do it.
The researchers used Claude models to investigate vulnerable software and develop exploits. An earlier model struggled with part of the challenge.
Then Anthropic released a more capable model.
The researchers gave the new model essentially the same problem.
Within hours, it succeeded.
❓ The Big Question: What Happens When AI Hacking Scales Expertise?
What happens when hacking stops being limited by the number of people who know how to hack?
For decades, cybersecurity enjoyed an accidental defense.
Complexity.
A vulnerability might exist publicly, but transforming an obscure software bug into a reliable attack could require rare expertise, intimate knowledge of computer systems, and weeks or months of painstaking work.
The door might technically be unlocked.
Almost nobody knew how to open it.
AI is beginning to change that economics.
Hacktron says its broader research campaign involved only three researchers, cost less than $3,000 in AI tokens, and allowed the team to adapt attacks to new targets in as little as one or two days.
The researchers emphasize that this was not fully autonomous hacking—skilled human direction remained important—but say AI dramatically increased what their small team could accomplish.
⭐ Why It’s Important
We often talk about AI replacing expertise.
Cybersecurity reveals something potentially more immediate:
AI can multiply expertise.
One exceptional security researcher with powerful AI may increasingly accomplish work that once demanded an exceptional security team.
That is wonderful when the researcher finds the vulnerability first, reports it responsibly, and helps get it fixed—as happened here.
The arithmetic becomes less comforting when the person on the keyboard has different intentions.
For years, companies could quietly depend on an uncomfortable fact: exploiting difficult vulnerabilities was expensive.
Attackers had limited time, limited talent, and limited resources.
Hacktron argues that AI hacking is turning some of that scarce expertise into something much easier to buy:
Compute.
That changes cybersecurity in a profound way.
The number of vulnerable doors may not suddenly increase.
The number of people capable of opening them might.
Enjoyed this article?
Stay ahead of the curve by subscribing to NewBits Digest, our weekly newsletter featuring curated AI stories, insights, and original content—from foundational concepts to the bleeding edge.
👉 Register or Login at newbits.ai to like, comment, and join the conversation.
Want to explore more?
AI Solutions Directory: Discover AI models, tools & platforms.
AI Ed: Learn through our podcast series, From Bits to Breakthroughs.
AI Hub: Engage across our community and social platforms.
Follow us for daily drops, videos, and updates:
And remember, “It’s all about the bits…especially the new bits.”



Comments