'The prophecy is fulfilled': Popular 2020 XKCD comic predicted 'HEIF Heist' OpenAI hack and even mentions ImageMagick in spooky coincidence
Fast forward to 2026, and researchers rode ImageMagick straight into OpenAI's internal GitHub.
A recent hack on OpenAI's Discourse forum exposed a shocking vulnerability that hackers were able to exploit, ultimately gaining access to ChatGPT and Codex accounts. The attackers used a combination of techniques, starting with a libheif heap overflow, which was then leveraged through ImageMagick on OpenAI's forum. This was made possible by a flaw in OpenAI's Single Sign-On (SSO) system, which allowed the attackers to take over employee accounts.
The researchers behind the hack found a familiar picture in an XKCD comic from 2020, which eerily predicted the very hack they were conducting. The comic's alt-text reads, "Someday ImageMagick will finally break for good, and we'll have a long period of scrambling as we try to reassemble civilization from the rubble." While the comic was originally published six years prior, the researchers noted that the situation was eerily prophetic, as ImageMagick was indeed present in the exact spot the breach ran through.
The vulnerability was caused by a heap buffer overflow issue in the libheif library, which was indirectly pulled in through ImageMagick. The researchers exploited this vulnerability to chain multiple exploits, ultimately gaining access to the target systems. OpenAI patched the issue within 14 hours of discovery, awarding the team a $6,500 bug bounty. However, the researchers warned that the same vulnerability could potentially be found in other production systems that use ImageMagick, libheif, and libde265 decoders.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.