Hacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
Introducing Hacktron Review: an AI security reviewer for your pull requests.
It understands your whole codebase, builds a threat model, takes your feedback, and catches exploitable vulnerabilities before they reach production.
Try for free: app.hacktron.ai
New YouTube video! We are looking at the dependency chain and how long it can take for security fixes to travel upstream.
This is why OpenAI was vulnerable to a 1-year-old vulnerability.
We found a flaw in Cluely.
it's built to be invisible. that's the selling point.
but think about it. an app nobody can see is also an app nobody can check.
it had your screen and your mic. one missing guard meant a single click could've handed both to a stranger. no warning, no prompt.
(found and patched back in 2025.)
AI apps are getting deeper access every month, and almost nobody reviews what they're shipping.
that's what we do. we check before it's watching you.
full breakdown here: hacktron.ai/blog/hacking-cluโฆ
๐ New Customer Story | Hacktron x Nopan
In payments, every pull request is a risk decision.
Nopan already combined peer review with automated testing, static analysis, and dependency scanning.
Hacktron adds context-aware review that surfaces complex, non-obvious risks in the relevant code without slowing delivery.
๐ Read the story: hacktron.ai/customer-storiesโฆ
oh wow!! agents scary!!! escaping sandboxes!! thermal side channels!!
how about you let us try escaping your sandbox first? patch what we find, implement defense in depth, then weโll see if your agents can do shit.
be like vercel.
Google Chrome. Full break-in.
Your product isn't secure. it's just been expensive to break. those are not the same thing, and a lot of founders are about to learn the difference.
One AI just ran the full chain into Chrome for $1,597. weeks of expert human work, done for the cost of a weekend trip.
The wall around your code was never "how good is this." it was "how much does it cost to find the crack." that cost is collapsing.
If breaking in is getting this cheap, checking your own code before someone else does can't be the thing you skip.
That's the gap we sit in. we run this on your code first.
We published every number. Read the full benchmark: hacktron.ai/blog/watching-gpโฆ
An OpenAI model hacked Hugging Face.
Nobody wrote that exploit. Nobody asked for it. It was stuck on a challenge it couldn't solve, so it went looking for the answer somewhere else.
Security has always assumed an attacker is a person. Someone with a motive, a budget, a reason to pick you. Threat models, red teams, patch cycles, all built on that.
Two things just broke:
โ Intent is optional. It wasn't told to break in. That was just the shortest path to finishing the task
โ Patience is free. A model doesn't get tired or bored. Give it enough compute and it will read your entire codebase until it finds something
Which is a rough spot for open source. If your code is public, it's already being read that way.
So the question isn't "who would bother targeting us." It's "what happens when we're the easiest way for something to finish its job."
Thatโs the gap we sit in. Hacktron reviews every code change before it ships, because the only thing fast enough to catch what AI breaks is AI.
Read the full blog here {12 min read}: hacktron.ai/blog/here-is-howโฆ
๐ฌ๐ผ๐ ๐ป๐ผ๐ ๐ด๐ฒ๐ ๐๐ผ ๐๐ฒ๐ฒ ๐๐ต๐ฎ๐ ๐ผ๐๐ฟ ๐ฎ๐ด๐ฒ๐ป๐๐ ๐ฑ๐ผ ๐๐ถ๐๐ต ๐ฒ๐๐ฒ๐ฟ๐ ๐ฝ๐ผ๐๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ณ๐ถ๐ป๐ฑ๐ถ๐ป๐ด
Our new Whitebox Pentest UI makes dynamic validation easier to follow. Watch our agents authenticate through the live browser preview, then see the actions they take to determine whether an issue can be reproduced against your running application and verify its impact.
Each validation returns a verdict with the relevant source references.
Less guesswork. More evidence.
Live now at app.hacktron.ai
๐๐ฎ๐ฐ๐ธ๐๐ฟ๐ผ๐ป ๐ถ๐ ๐ป๐ผ๐ ๐ฆ๐ข๐ ๐ฎ ๐ง๐๐ฝ๐ฒ ๐๐ ๐ฐ๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ ๐
This means greater assurance over how we protect data and operate our systems.
Next up: ๐๐๐ฏ๐ฒ๐ฟ ๐ง๐ฟ๐๐๐ ๐ ๐ฎ๐ฟ๐ธ, ๐๐ฆ๐ข ๐ฎ๐ณ๐ฌ๐ฌ๐ญ ๐ฎ๐ป๐ฑ ๐๐ฅ๐๐ฆ๐ง as we continue strengthening the standards behind how we operate and deliver security services.
We Hacked OpenAI.
Here's what didn't fit in 90 seconds:
โ OpenAI was only one target. It was part of a bigger research project we call the HEIF Heist
โ 2 months, 3 researchers, under $3,000 in AI tokens
โ The bug we used had already been fixed upstream. It just never got a CVE, so it never got patched downstream
โ The older Claude model got stuck. Claude Opus 5 cracked it within hours of release
โ OpenAI paid us $6,500 for the finding :).
The scary part isn't OpenAI. They fixed it in 14 hours.
It's every other company running the same image software, still unpatched, with no CVE telling them to care.
Harsh, Mohan and Rahul wrote up everything.
Visit - Hacktron.ai/blog/hacking-opeโฆ
A single malicious image led to demonstrated access to an internal OpenAI repository ๐
This is the exploit chain that took our researchers from a vulnerable libheif dependency in the OpenAI Community forum to internal repo access.
Full technical breakdown: hacktron.ai/blog/hacking-opeโฆ
We collaborated with @HacktronAI to reproduce the libheif vulnerability in Next.js and responsibly disclose it to the maintainer.
Learn about the dependency chain and fix โ
vercel.com/blog/reproducing-โฆ
We are not stopping at OpenAI.
Today weโre publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif.
The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others.
heif-heist.com
Weโre disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more.
It was literally xkcd #234, one obscure image library beneath a huge number of apps. ๐งต