By Evan Vega
Three security researchers reached inside OpenAI this summer. Not as criminals, and not by accident. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of the security firm Hacktron AI ran an authorized test under OpenAI’s own bug-bounty program, proved they could reach an internal code repository with a single harmless action, and stopped. OpenAI confirmed a fix within about fourteen hours and paid a $6,500 bounty. This is how responsible disclosure is supposed to work.
The unsettling part is not the break. It is the receipt. The entire two-month project cost the team under $3,000 in AI tokens, and its hardest step only succeeded because a newer AI model shipped in the middle of the work. This is a report on what that means, at the level of cost, capability and policy. No method appears here by choice.
Three researchers at Hacktron AI ran an authorized bug-bounty test and reached OpenAI’s internal systems; OpenAI paid $6,500 and fixed it in about 14 hours. The story is not the hack. The whole two-mo
This becomes a public-policy story when you set it beside the other trend line. As AI-assisted offense grew cheaper in 2026, the country’s civilian cyber-defense agency was thinned. CISA has lost roughly a third of its workforce since January 2025 and has had no permanent director in that time. The budget proposed for the next year would cut it further — on the order of hundreds of millions of dollars and hundreds of positions, including a roughly 60 percent cut to the work of running government penetration tests.
There is, in fairness, a Trump administration executive order aimed at roughly this, a framework for early government access to test frontier models. But an order on paper does not close a gap; funded people do, and the proposal is to have fewer of them. The figures, with both endpoints and both framings, are at The Defense Gap.
Strip out the target and the reward and one detail is the story. The hardest part of the work did not yield to effort. It yielded to a release. For weeks, Claude Opus 4.8 could not finish the key step across repeated sessions. Then Opus 5 shipped, mid-project, and in the researchers’ own words a task the older model had failed across several sessions was solved by the newer one within hours of its release.
“AI can hack” has been a headline for two years. This is sharper. The capability frontier for real offensive work is moving in visible steps, and each step is a scheduled product launch. A defender who was safe against the tooling in June was not safe in late July, and nothing on their end changed. Their exposure moved on a calendar they do not control. The full walk-through is at The Model Jump.
The bounty was $6,500. The project cost under $3,000 in tokens. Security has quietly relied on cost as a control for decades: the assumption that work this deep needed a funded team and a long runway, so only serious, rare actors could afford it. That assumption broke this summer, and it broke quietly.
When the price of an attempt falls by an order of magnitude, more people can try and each skilled person can run more attempts at once. The threat model built for a small number of expensive actors does not survive a large number of cheap ones. The point is not panic. It is to stop pricing risk on last year’s cost of an attack. The full reasoning is at Under Three Thousand, and the guardrail question — a refusal that held until it was reworded — is at The Refusal.
The event itself was good-faith work by skilled people, disclosed and fixed, and the researchers handled it well. The lesson is not about them. It is that the floor for this kind of work dropped hard this year, that a single model release can move it again without warning, and that the safety net most organizations quietly count on is being cut rather than grown.
The full analysis, with both ends of every date and every figure sourced, is at cheapoffense.novcog.us.com: What Happened, The Model Jump, The Defense Gap, and Sources & Method. Primary source: the researchers’ own writeup at hacktron.ai; corroborated by The Register, Malwarebytes and The Next Web.
Part of the Frontier Watch Series: Read the previous investigation
More Coverage:
→ Read this investigation on North Denver Tribune
→ Coverage from Daily Colorado News