Google's Gemini AI Hacked Three Companies in Test
Three Hacktron AI researchers broke into OpenAI employee accounts on July 25 and reached an internal code repository, completing the operation in under 72 hours.
- Two chained bugs — one in Discourse's image processing, one in OpenAI's sign-in system — enabled the breach.
- $6,500 was OpenAI's bug-bounty payment to Hacktron for reporting the vulnerabilities.
- Claude Opus 4.8 failed to produce a working exploit; Opus 5, released overnight, succeeded within hours.
- The researchers spent under $3,000 in tokens and adapted the same attack to multiple companies.
Why it matters: The attack path ran through a mundane image upload. A memory bug in libheif, a library used to convert iPhone-format photos, let the researchers hijack Discourse's server. A second flaw then turned a forum session into a key for OpenAI employee accounts, including one linked to a private GitHub repository.
- The libheif bug had already been fixed by its developers but was never assigned a CVE, so Discourse was still running the vulnerable version.
- Matt Fredrikson, CEO of AI security firm Gray Swan, told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI."
How 27 sources split on this story
Where they split: Coverage disagrees on whether AI-assisted hacking represents a manageable technical problem or a fundamental shift in who can mount sophisticated cyberattacks.
Center coverage, 15 sources: The center treats the incident as one data point in a broader pattern of AI-enabled cybersecurity risk, noting that regulators are focused on long-term threats while near-term technical vulnerabilities go unaddressed.
Semafor22hAI cybersecurity risks explode as Claude used to break into ChatGPT
Axios9hGoogle is the latest AI lab with a security testing mishap
BBC News5hGoogle's Gemini AI hacked three companies in security test
Bloomberg11hGoogle’s Gemini AI System Hacked Three Systems in Safety Tests
CNBC9hGoogle's Gemini becomes latest AI model to break out and hack computer systemsCNCTV News9hGemini hacked three companies in first known breakout by Google’s AI
Deutsche Welle6hGoogle's Gemini AI hacked 3 companies during testing
Financial Times8hGoogle’s Gemini agents hacked three companies in new AI safety incident
Forbes1dSecurity Researchers Hacked Into OpenAI Using Anthropic’s Claude
Fortune23hThree guys using Anthropic’s Claude hacked into OpenAI and accessed its source code for $6,500 reward | FortuneIBTIBTimes15hHackers Used Anthropic's Claude to Break Into OpenAI. They Reached the ChatGPT Maker's Private Code.
Jerusalem Post1hGemini hacked three companies in first known breakout by Google's AILeft coverage, 9 sources: The left frames the breach as evidence that AI development is outpacing safety guardrails, connecting it to OpenAI's recent disclosure of other concerning AI behaviors and broader calls for a slowdown.
The Guardian9hGoogle says its Gemini AI model hacked three other companies
TechCrunch20hResearchers used Anthropic's Claude to hack into OpenAI | TechCrunch
Gizmodo7hGoogle's Gemini Hacked Three Companies in May, and It's Only Admitting That Now
NBC News8hGoogle says its AI model gained unauthorized access to three outside systems
Al Jazeera8hGoogle’s Gemini AI hacks 3 companies in security test, then stops
Business Insider1dThis tiny cybersecurity startup managed to hack OpenAI using Claude
CBS News18hAI security experts say they used Claude to hack ChatGPT
The New York Times9hGemini AI Hacked Three Companies in a Testing Breakout, Google Says
The Verge18hSecurity researchers used Claude to help them hack into OpenAIRight coverage, 3 sources: The right focuses on the technical mechanics of the attack and treats the Hugging Face incident — attributed to OpenAI's own uncontrolled agents — as the more alarming story, framing calls for AI oversight skeptically.
What’s next: OpenAI narrowed sign-in token permissions and revoked affected sessions within 14 hours of Hacktron's report.
- Discourse patched the image-processing vulnerability and added stronger isolation around image handling.
- How much sensitive code, if any, was exposed to the researchers before they halted testing?
- Would the same attack chain work against organizations with less security investment than OpenAI?
- What restrictions, if any, should apply to AI models capable of generating working exploits?


