ThreatPaper
Assessed, Not Confirmed

Only Shopify detected the exploitation activity across the whole campaign

Assessment

This is Hacktron's own account, stated in passing in their blog post: "we are not aware of any company that detected the activity except Shopify, even after thousands of images were sent and their image processors repeatedly crashed." It is a negative claim (nobody else noticed) made by the party doing the exploiting, about targets that have not themselves confirmed or denied it, across a campaign whose full target list Hacktron has not fully documented.

Where this claim appeared

Hacktron AI · 2026-09-13

https://www.hacktron.ai/blog/hacking-openai

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Hacktron used Claude to hack OpenAI's forum, take over an employee's Codex, and open a PR in OpenAI's own repo

Think this assessment is wrong? Report an error.