Security researchers at Hacktron AI discovered a memory-corruption bug in an image library used by OpenAI's forum, then used Anthropic's Claude Opus 5 to develop a working exploit that achieved remote code execution and access to OpenAI's private repositories within 72 hours. The vulnerability stemmed from an unpatched libheif flaw in Discourse combined with excessive permissions in OpenAI's single sign-on system.