Security· ★★★· neutral·

RobinhoodCrypto vulnerability chain ran from HEIF upload to GitHub access

  • The chain began with a heap overflow during HEIF image upload and reached remote code execution
  • An SSO weakness expanded access to ChatGPT, Codex and internal GitHub pull requests
  • The full attack chain was assembled in under 72 hours with the help of AI
  • The vulnerabilities were fixed within 14 hours of disclosure
Why it matters: It shows that AI accelerates the discovery of vulnerability chains, and that security depends on the entire chain of services rather than individual components.
Source: CoinTrust