Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO

Latent Space
Introducing Hacktron Review: an AI security reviewer for your pull requests. It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production. Try for free: app.hacktron.ai
22
42
285
72,329
New YouTube video! We are looking at the dependency chain and how long it can take for security fixes to travel upstream. This is why OpenAI was vulnerable to a 1-year-old vulnerability.
4
5
67
5,313
We found a flaw in Cluely. it's built to be invisible. that's the selling point. but think about it. an app nobody can see is also an app nobody can check. it had your screen and your mic. one missing guard meant a single click could've handed both to a stranger. no warning, no prompt. (found and patched back in 2025.) AI apps are getting deeper access every month, and almost nobody reviews what they're shipping. that's what we do. we check before it's watching you. full breakdown here: hacktron.ai/blog/hacking-cluโ€ฆ
1
37
2,844
๐ŸŽ‰ New Customer Story | Hacktron x Nopan In payments, every pull request is a risk decision. Nopan already combined peer review with automated testing, static analysis, and dependency scanning. Hacktron adds context-aware review that surfaces complex, non-obvious risks in the relevant code without slowing delivery. ๐Ÿ‘‡ Read the story: hacktron.ai/customer-storiesโ€ฆ
2
26
1,960
oh wow!! agents scary!!! escaping sandboxes!! thermal side channels!! how about you let us try escaping your sandbox first? patch what we find, implement defense in depth, then weโ€™ll see if your agents can do shit. be like vercel.
8
7
267
19,981
Google Chrome. Full break-in. Your product isn't secure. it's just been expensive to break. those are not the same thing, and a lot of founders are about to learn the difference. One AI just ran the full chain into Chrome for $1,597. weeks of expert human work, done for the cost of a weekend trip. The wall around your code was never "how good is this." it was "how much does it cost to find the crack." that cost is collapsing. If breaking in is getting this cheap, checking your own code before someone else does can't be the thing you skip. That's the gap we sit in. we run this on your code first. We published every number. Read the full benchmark: hacktron.ai/blog/watching-gpโ€ฆ
6
29
184
24,527
15
8
457
62,530
An OpenAI model hacked Hugging Face. Nobody wrote that exploit. Nobody asked for it. It was stuck on a challenge it couldn't solve, so it went looking for the answer somewhere else. Security has always assumed an attacker is a person. Someone with a motive, a budget, a reason to pick you. Threat models, red teams, patch cycles, all built on that. Two things just broke: โ†’ Intent is optional. It wasn't told to break in. That was just the shortest path to finishing the task โ†’ Patience is free. A model doesn't get tired or bored. Give it enough compute and it will read your entire codebase until it finds something Which is a rough spot for open source. If your code is public, it's already being read that way. So the question isn't "who would bother targeting us." It's "what happens when we're the easiest way for something to finish its job." Thatโ€™s the gap we sit in. Hacktron reviews every code change before it ships, because the only thing fast enough to catch what AI breaks is AI. Read the full blog here {12 min read}: hacktron.ai/blog/here-is-howโ€ฆ
1
49
3,859
๐Ÿ‘€๐Ÿ‘€
heif heist? @HacktronAI moving exploitation base to san francisco hit us up, would love to meet people.
1
1
23
3,478
Hacktron AI retweeted
๐—ฌ๐—ผ๐˜‚ ๐—ป๐—ผ๐˜„ ๐—ด๐—ฒ๐˜ ๐˜๐—ผ ๐˜€๐—ฒ๐—ฒ ๐˜„๐—ต๐—ฎ๐˜ ๐—ผ๐˜‚๐—ฟ ๐—ฎ๐—ด๐—ฒ๐—ป๐˜๐˜€ ๐—ฑ๐—ผ ๐˜„๐—ถ๐˜๐—ต ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฝ๐—ผ๐˜๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ณ๐—ถ๐—ป๐—ฑ๐—ถ๐—ป๐—ด Our new Whitebox Pentest UI makes dynamic validation easier to follow. Watch our agents authenticate through the live browser preview, then see the actions they take to determine whether an issue can be reproduced against your running application and verify its impact. Each validation returns a verdict with the relevant source references. Less guesswork. More evidence. Live now at app.hacktron.ai
2
2
27
1,507
๐—›๐—ฎ๐—ฐ๐—ธ๐˜๐—ฟ๐—ผ๐—ป ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐—ฆ๐—ข๐—– ๐Ÿฎ ๐—ง๐˜†๐—ฝ๐—ฒ ๐—œ๐—œ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—น๐—ถ๐—ฎ๐—ป๐˜ ๐ŸŽ‰ This means greater assurance over how we protect data and operate our systems. Next up: ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—ง๐—ฟ๐˜‚๐˜€๐˜ ๐— ๐—ฎ๐—ฟ๐—ธ, ๐—œ๐—ฆ๐—ข ๐Ÿฎ๐Ÿณ๐Ÿฌ๐Ÿฌ๐Ÿญ ๐—ฎ๐—ป๐—ฑ ๐—–๐—ฅ๐—˜๐—ฆ๐—ง as we continue strengthening the standards behind how we operate and deliver security services.
3
2
55
3,562
We Hacked OpenAI. Here's what didn't fit in 90 seconds: โ†’ OpenAI was only one target. It was part of a bigger research project we call the HEIF Heist โ†’ 2 months, 3 researchers, under $3,000 in AI tokens โ†’ The bug we used had already been fixed upstream. It just never got a CVE, so it never got patched downstream โ†’ The older Claude model got stuck. Claude Opus 5 cracked it within hours of release โ†’ OpenAI paid us $6,500 for the finding :). The scary part isn't OpenAI. They fixed it in 14 hours. It's every other company running the same image software, still unpatched, with no CVE telling them to care. Harsh, Mohan and Rahul wrote up everything. Visit - Hacktron.ai/blog/hacking-opeโ€ฆ
6
16
157
9,379
A single malicious image led to demonstrated access to an internal OpenAI repository ๐Ÿ‘‡ This is the exploit chain that took our researchers from a vulnerable libheif dependency in the OpenAI Community forum to internal repo access. Full technical breakdown: hacktron.ai/blog/hacking-opeโ€ฆ
4
30
237
10,423
Hacktron AI retweeted
"3 random dudesโ€ 1. hacked apple, again and again. httpvoid.com/Apple-RCE.md httpvoid.com/Hello-Lucee!-Leโ€ฆ httpvoid.com/Hacking-Apple-wโ€ฆ 2. your github enterprise is our github enterprise. httpvoid.com/GitHub-Enterpriโ€ฆ 3. get a discord message from me, get pwned. hacktron.ai/blog/discord-rce piped.video/watch?v=R3SE4VKjโ€ฆ 4. oh yeah, at one point we basically had shells across the electron ecosystem. check the DEF CON research. media.defcon.org/DEF%20CON%2โ€ฆ 5. your supabase database is my database. hacktron.ai/blog/supapwn 6. we got the posthog prod database. hacktron.ai/blog/posthog-rce 7. react2shell? vercel paid us $170k for helping secure their waf. hacktron.ai/blog/react2shellโ€ฆ 8. your palo alto vpn is my vpn. hacktron.ai/blog/cve-2026-02โ€ฆ 9. ai ides? we got shells for you, antigravity hacktron.ai/blog/hacking-gooโ€ฆ 10. windsurf rce. piped.video/watch?v=23Mz7qcRโ€ฆ 11. turning cluely into malware. hacktron.ai/blog/hacking-cluโ€ฆ 12. ai browsers? sure, uxss: your perplexity browser is my browser. hacktron.ai/blog/perplexity-โ€ฆ 13. openai atlas too. kinda uxss hacktron.ai/blog/hacking-opeโ€ฆ 14. hey, itโ€™s not even our first time hacking discourse. projectdiscovery.io/blog/disโ€ฆ 15. adobe coldfusion: pre-auth rce. because apparently we needed another one. projectdiscovery.io/blog/adoโ€ฆ thereโ€™s a lot more. go dig. anyway, yes: โ€œ3 random dudes.โ€ and @HacktronAI is full of more random dudes like these.
70
239
2,090
180,751
We are not stopping at OpenAI. Today weโ€™re publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif. The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others. heif-heist.com
15
105
820
48,863
Weโ€™ll be disclosing the technical details behind the major affected platforms and projects over the coming weeks at: hacktron.ai/blog?utm_source=โ€ฆ
1
1
11
1,367
Research by @rootxharsh, @S1r1u5_, and @iamnoooob.
Weโ€™re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. ๐Ÿงต
1
14
1,513