Cheap Offense: A $3,000 Test Reached Inside OpenAI, and a Model Release Is Why

Posted

By Evan Vega

Three security researchers reached inside OpenAI this summer. Not as criminals, and not by accident. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of the security firm Hacktron AI ran an authorized test under OpenAI’s own bug-bounty program, proved they could reach an internal code repository with a single harmless action, and stopped. OpenAI confirmed a fix within about fourteen hours and paid a $6,500 bounty. This is how responsible disclosure is supposed to work.

The unsettling part is not the break. It is the receipt. The entire two-month project cost the team under $3,000 in AI tokens, and its hardest step only succeeded because a newer AI model shipped in the middle of the work. This is a report on what that means, at the level of cost, capability and policy. No method appears here by choice.

The full analysis — the authorized test, the model-generation jump that made it cheap, the guardrail that held only until it was reworded, and the defensive agency being cut at the same time. Seven minutes.

Three researchers at Hacktron AI ran an authorized bug-bounty test and reached OpenAI’s internal systems; OpenAI paid $6,500 and fixed it in about 14 hours. The story is not the hack. The whole two-mo

Offense got cheap. Public defense got cut.

This becomes a public-policy story when you set it beside the other trend line. As AI-assisted offense grew cheaper in 2026, the country’s civilian cyber-defense agency was thinned. CISA has lost roughly a third of its workforce since January 2025 and has had no permanent director in that time. The budget proposed for the next year would cut it further — on the order of hundreds of millions of dollars and hundreds of positions, including a roughly 60 percent cut to the work of running government penetration tests.

There is, in fairness, a Trump administration executive order aimed at roughly this, a framework for early government access to test frontier models. But an order on paper does not close a gap; funded people do, and the proposal is to have fewer of them. The figures, with both endpoints and both framings, are at The Defense Gap.

A version number did what effort could not

Strip out the target and the reward and one detail is the story. The hardest part of the work did not yield to effort. It yielded to a release. For weeks, Claude Opus 4.8 could not finish the key step across repeated sessions. Then Opus 5 shipped, mid-project, and in the researchers’ own words a task the older model had failed across several sessions was solved by the newer one within hours of its release.

“AI can hack” has been a headline for two years. This is sharper. The capability frontier for real offensive work is moving in visible steps, and each step is a scheduled product launch. A defender who was safe against the tooling in June was not safe in late July, and nothing on their end changed. Their exposure moved on a calendar they do not control. The full walk-through is at The Model Jump.

When offense costs less than a laptop

The bounty was $6,500. The project cost under $3,000 in tokens. Security has quietly relied on cost as a control for decades: the assumption that work this deep needed a funded team and a long runway, so only serious, rare actors could afford it. That assumption broke this summer, and it broke quietly.

When the price of an attempt falls by an order of magnitude, more people can try and each skilled person can run more attempts at once. The threat model built for a small number of expensive actors does not survive a large number of cheap ones. The point is not panic. It is to stop pricing risk on last year’s cost of an attack. The full reasoning is at Under Three Thousand, and the guardrail question — a refusal that held until it was reworded — is at The Refusal.

Price your risk on this year’s cost

The event itself was good-faith work by skilled people, disclosed and fixed, and the researchers handled it well. The lesson is not about them. It is that the floor for this kind of work dropped hard this year, that a single model release can move it again without warning, and that the safety net most organizations quietly count on is being cut rather than grown.

The full analysis, with both ends of every date and every figure sourced, is at cheapoffense.novcog.us.com: What Happened, The Model Jump, The Defense Gap, and Sources & Method. Primary source: the researchers’ own writeup at hacktron.ai; corroborated by The Register, Malwarebytes and The Next Web.


Part of the Frontier Watch Series: Read the previous investigation

.


More Coverage:
→ Read this investigation on North Denver Tribune
→ Coverage from Daily Colorado News

The post Cheap Offense: A $3,000 Test Reached Inside OpenAI, and a Model Release Is Why first appeared on DAILY TEXAS NEWS.
News, AI capabilities, AI policy, AI security, Anthropic, bug bounty, CISA, Claude, Claude Opus 5, cybersecurity, Hacktron, OpenAI, responsible disclosure