ThreatPaper
Assessed, Not Confirmed

Researchers used Claude to hack Slack, Meta, Zoom, Shopify, GitHub Enterprise "and many more"

Assessment

Hacktron's own blog frames a broader "HEIF Heist" project spanning these platforms, and a promotional video goes further, claiming the team "hacked Slack, Meta, and many more." But the published post documents only the OpenAI case with a timeline, exploit chain, disclosure record and named CVE; VentureBeat's independent reporting explicitly notes the other companies are named only as part of the wider campaign, without matching technical detail or any vendor confirmation. No advisory from any of those companies has surfaced.

Where this claim appeared

VentureBeat · 2026-09-17

https://venturebeat.com/security/openai-hacked-by-small-team-of-white-hat-security-researchers-using-anthropics-claude-opus-5

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Hacktron used Claude to hack OpenAI's forum, take over an employee's Codex, and open a PR in OpenAI's own repo

Think this assessment is wrong? Report an error.