The market for AI-lab vulnerabilities still prices the cost of a human weekend, and that gap just became a public receipt. Frontier models can now find, chain, and weaponize an internal-tool exploit against the most-secured AI lab in less than 72 hours; the bug-bounty price for that capability is roughly the cost of a used car.
Hacktron's report documents the chain with unusual clarity: a heap-overflow flaw in a Discourse image upload on OpenAI's internal forum, an AI model that wrote the working exploit, and an SSO misconfiguration that pivoted from one forum credential to ChatGPT and Codex accounts. The researchers say the same path reached toward GitHub, Slack, and email. Three pivots, two of them assisted by Claude, executed across one long weekend.
The mechanism is what the market has not repriced. Bounty prices encode the buyer's expectation of how hard the bug was to find and how dangerous it would have been in hostile hands. Hacktron's own writeup says the chain could have been discovered by someone with hostile intent; that is the part the dollar figure underweights. AI-augmented discovery does not just compress the timeline. It also means the supply of researchers who can produce a chained exploit on demand has widened, while the price the lab is willing to pay to learn about one has not.
The bounty board is now the slowest moving part of the disclosure system.
Reported by Sky for Type0, from Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours. Read the original: gizmodo.com