Moneycontrol PRO
LAMF
LAMF

OpenAI denies user data breach after Axios developer tool compromise; asks macOS users to update apps

OpenAI says no user data or systems were compromised after an Axios-related incident, but macOS users must update apps as the company rotates security certificates.
April 12, 2026 / 12:25 IST
OpenAI
Snapshot AI
  • No user data or internal systems were compromised, says OpenAI
  • OpenAI revoked and rotated macOS app certificates as a precaution
  • macOS users must update apps; other platforms are unaffected

OpenAI has said that no user data or internal systems were compromised following a security issue linked to a third-party developer tool, Axios. The company confirmed that the incident was part of a broader software supply chain attack affecting the industry, but added that its investigation found no evidence of data exposure or software tampering.

What happened

According to the company, the issue originated from a compromised version of Axios that was briefly used in a GitHub Actions workflow tied to the macOS app-signing process. This workflow had access to certificates used to verify that OpenAI’s desktop applications are legitimate.

While the company stated that the likelihood of the certificate being extracted was low due to timing and safeguards, it is treating the certificate as potentially exposed. As a result, OpenAI has decided to revoke and rotate the certificate as a precautionary step.

What OpenAI is doing

OpenAI said it is updating its macOS code-signing certificates and releasing new builds of its desktop applications. Users will need to update to the latest versions to continue receiving updates and ensure app authenticity.

Older versions of OpenAI’s macOS apps will stop receiving support after May 8, 2026, and may not function as expected. The company has also worked with Apple to block any further notarisation attempts using the older certificate.

Impact on users

OpenAI clarified that the incident does not affect iOS, Android, Windows, Linux, or web users. It also confirmed that passwords, API keys, and user data remain safe.

However, macOS users are advised to update their apps through official channels or in-app updates. The company warned against downloading apps from third-party sources, emails, or unknown links, as attackers could attempt to distribute fake versions.

Security measures and response

As part of its response, OpenAI engaged external security experts, reviewed all notarisation activity, and confirmed that no unauthorised software was signed using its credentials. The company also fixed the underlying issue in its workflow, including replacing floating tags with specific versions and adding stricter controls.

OpenAI said it will continue monitoring for any misuse and may accelerate certificate revocation if suspicious activity is detected.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert:

It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347