Researchers chained bugs to compromise OpenAI ChatGPT accounts
Security group HacktronAI said they chained two critical vulnerabilities on July 25, 2026 to access multiple OpenAI employees' ChatGPT and Codex accounts, and created a harmless PR in OpenAI's internal repo as proof. They reported the issues to OpenAI and Discourse, received a $6,500 bounty, described an under-72-hour disclosure timeline, and noted using Claude models; the initial flaw included RCE in Discourse.