K Koda Intelligence
DEEP DIVE DEEP DIVE № 203 · 22 September 2026DOCKODA-20260922-AF911A57C801sha-256 of date + article + 21 claims
FILED 22 SEPTEMBER 202621 CLAIMS CHECKED · 9 VERIFIED

OpenAI's breach started with a photo,
not a prompt

Three researchers reached an internal OpenAI code repository in under 72 hours19 without touching a model. The entry point, per Hacktron's September 1311 disclosure, was libheif 1.19.701 on Debian 1206, the C library that decodes the HEIC photos iPhones shoot by default. The chain was reported to OpenAI and Discourse in July and quietly fixed. OpenAI paid a $6,50017 bounty for the sign-in finding. Every product with an attach-an-image button inherits the same loading dock.

2 MIN READ · BY THE KODA EDITORIAL TEAM · SECURITY · MULTIMODAL PIPELINES
BOUNTY PAID$6,500REPORTED CLAIM 17HACKTRON
TIME TO REPO72 HOURSVERIFIED CLAIM 19UNDER
RESEARCHERS3NOT MEASUREDHACKTRON
BOUNTY PAID$6,500HACKTRON TIME TO REPO72 HOURSUNDER RESEARCHERS3HACKTRON DISCLOSEDSEP 13HACKTRON DECODER BUILD1.19.7LIBHEIF HOST OSDEBIAN 12FORUM STACK CHAIN STEPS9PHOTO TO PULL REQUEST CODE BUCKETS3UPLOAD PATH

Three researchers broke into OpenAI's internal code repository in under 72 hours19. They did not attack a model. They uploaded a photo. According to Hacktron's September 1311 disclosure, the entry point was libheif, a C library that decodes the HEIC images modern iPhones shoot by default.

OpenAI paid a $6,50017 bounty, for its own sign-in finding only. The chain was reported to OpenAI and Discourse in July and fixed before the public heard a word, per VentureBeat. I will admit I skimmed past this story the first time because it read like a forum bug. That was a mistake.

The lesson is simple. Multimodal AI gets attacked through an image decoder, not a model. Every product with an "attach an image" button inherits the same problem, and most teams have never looked at it.

The Loading Dock Rule

Every AI product has a front door and a loading dock. The front door is the model: the prompt box, the safety layer, the thing your red team hammers all quarter. The loading dock is the upload pipeline, where raw bytes from strangers get unpacked by code written before your engineers learned to type. Attackers walk in wherever the oldest code touches untrusted input first.

UPLOAD PIPELINE LEDGER · SEPTEMBER 2026HACKTRON · VENTUREBEAT · OpenAI · DISCOURSEBASE: 21 CHECKED CLAIMS, 4 SHOWN

What it cost to walk from an image upload into an internal monorepo.

Bounty for OpenAI's own finding Sign-in flaw only · forum out of scope REPORTED CLAIM 17
$6,500
Time to reach the repository Three researchers · no model interaction VERIFIED CLAIM 19
72 HOURS
Vulnerable decoder version libheif on Debian 12 · called via magick VERIFIED CLAIM 01
1.19.7
Public disclosure date Reported in July · fixed before release VERIFIED CLAIM 11
SEP 13

Sort your upload path into three buckets. Modern managed code: decoders written in Rust, Go, or JavaScript with bounds checking built in. Wrapped legacy code: ImageMagick or libvips calling down into C parsers on your behalf. Naked legacy code: a C library linked straight into your app.

OpenAI's forum sat in bucket two, and bucket two is where most of the internet lives. Discourse itself is Ruby. The danger was one shell command deep, where magick handed a HEIC file to libheif 1.19.701 on Debian 1206.

The cash side matters here. A community forum exists to deflect support tickets, so to a marketing team it is free convenience. It was also wired to OpenAI's sign-in, and that sign-in reached far beyond the forum. OpenAI's bounty covered that sign-in flaw alone; testing the forum was outside its program's scope.

The loading dock nobody red-teamed

BUCKET TWO
1.19.701

Wrapped legacy code is where most of the internet lives.

A Ruby app on top does not make the C parser underneath safe. Many upload pipelines call a native image library the same way, and this one ran on Debian 1206. Managed code on top does not neutralise a C parser underneath.

SCOPE GAP
$6,50017

The bounty paid for one link, not the chain.

OpenAI's $6,500 covered its own sign-in flaw. Testing the forum was outside its bug bounty scope, so nothing was paid for the rest of the path.

FREE CONVENIENCE
7219 HOURS

A ticket-deflection tool became the front line.

A help forum looks low-stakes to the people who approve it. Its sign-in reached far more than the forum, and three researchers turned that into an internal code path in under 72 hours.

DOJO · BUILD THIS WEEKEND

Audit the loading dock before someone else does.

  1. Inventory every upload entry point. List every place a stranger can hand your systems raw bytes: product uploads, support forums, avatar fields, email attachments. The OpenAI chain started in a community forum, not the core product.
  2. Sort each decoder into three buckets. Modern managed code with bounds checking, wrapped legacy code such as ImageMagick or libvips shelling into C parsers, and naked legacy C linked into your app. Anything in bucket two or three needs a named owner and a patch cadence.
  3. Pin and test your image library versions. Record the exact build in use, as Hacktron did with libheif 1.19.701 on Debian 1206, then fuzz HEIC and other camera-native formats against it in a sandbox with no network and no repository credentials.
Train the full skill in The Dojo
THE BOTTOM LINE

Your red team is guarding the front door while the loading dock stands open.

The July chain against OpenAI earned a $6,50017 bounty and less than 72 hours19 to build, and it never attacked a model. It went through libheif 1.19.701, C code sitting quietly behind a Ruby forum on Debian 1206. That is the shape of multimodal risk: the newest interface on your product is wired to the oldest code in your stack, and prompt-injection drills will not find it. Map the upload path, name the owner of every decoder, and treat the attach-an-image button as untrusted input rather than free convenience.

WATCH · VISUAL NARRATIVEAnimated breakdown · ~6 min
PLAY · YOUTUBE
EDITORIAL RECEIPTKODA-20260922-AF911A57C801
As of22 September 2026MethodClaim extraction, dated-evidence review, and temporal consistency gate. Corrected 22 September 2026: the $6,500 bounty covered OpenAI's sign-in finding only, not the chain; repeated card text and an empty section heading removed.CorrectionsContact the Koda desk
EVIDENCE21 CLAIMS CHECKED · 9 VERIFIED · 12 REPORTED
9 verified12 reported
  1. 01In the OpenAI forum exploit, the `magick` command handed a HEIC file to libheif version 1.19.7.VERIFIEDTRUEMODELcybersecuritynews.com
  2. 02libheif is a C library that decodes HEIC images.REPORTEDMOSTLY TRUEFEATUREgithub.com
  3. 03Every iPhone shoots HEIC images by default.REPORTEDMOSTLY TRUEFEATURECORRECTED IN COPYheicify.com
  4. 04ImageMagick and libvips call down into C parsers to decode images.VERIFIEDTRUEFEATUREgithub.com
  5. 05Discourse is written in Ruby.REPORTEDMOSTLY TRUEFEATUREross.abutalabs.com
  6. 06OpenAI's community forum was running on Debian 12 at the time of the libheif exploit.VERIFIEDTRUEFEATUREwindowsforum.com
  7. 07OpenAI's community forum is hosted at community.openai.com.VERIFIEDTRUEFEATUREcommunity.openai.com
  8. 08Discourse normally runs uploaded files through FastImage for a sanity check.REPORTEDMOSTLY TRUEFEATURECORRECTED IN COPYwebairadar.com
  9. 09FastImage does not support the HEIF image format.REPORTEDMOSTLY TRUEFEATURECORRECTED IN COPYwebairadar.com
  10. 10In Discourse, uploaded HEIC files skip the FastImage sanity check and go to ImageMagick.VERIFIEDTRUEFEATUREwebairadar.com
  11. 11Hacktron published its disclosure of the OpenAI code repository breach on September 13.VERIFIEDTRUEATTRIBUTIONxenospectrum.com
  12. 12According to Hacktron's disclosure, the entry point for the OpenAI internal code repository breach was libheif.REPORTEDMOSTLY TRUEATTRIBUTIONqz.com
  13. 13According to VentureBeat, the libheif exploit chain was reported to OpenAI and Discourse in July.REPORTEDMOSTLY TRUEATTRIBUTIONventurebeat.com
  14. 14According to VentureBeat, the libheif exploit chain against OpenAI's forum was fixed before it was publicly disclosed.VERIFIEDTRUEATTRIBUTIONventurebeat.com
  15. 15Claim removed during the check; its text is not republished.REPORTEDMIXEDATTRIBUTIONCUT FROM COPYglonce.com
  16. 16According to Hacktron, the upstream libheif security fix missing from version 1.19.7 was shipped without a CVE being assigned.REPORTEDMOSTLY TRUEATTRIBUTIONcyberkendra.com
  17. 17The bug bounty paid for the libheif exploit chain that reached OpenAI's internal code repository was $6,500.REPORTEDMOSTLY TRUEPRICEtechaiwire.com
  18. 18The $6,500 bounty was paid for reaching an OpenAI internal monorepo via the OpenAI community forum.REPORTEDMOSTLY TRUEPRICEtrendingtopics.eu
  19. 19Three researchers broke into OpenAI's internal code repository in under 72 hours.VERIFIEDTRUEHISTORYqz.com
  20. 20The researchers who broke into OpenAI's internal code repository did so by uploading a photo, not by attacking a model.REPORTEDMOSTLY TRUEHISTORYxenospectrum.com
  21. 21Hacktron's write-up of the OpenAI forum exploit lays out nine steps.VERIFIEDTRUESTATsecurityweek.com

Every claim listed here was extracted from this article and checked against live sources before publication. The verdict is the checker's, not the writer's. Claims the check removed are counted but not republished.

Audit receipt KODA-20260922-AF911A57C801
Filed underSecurityDeep Dive22 September 2026
Browse the Deep Dive archive

Get the morning Signal

179 editions so far, one a day. Unsubscribe anytime.