Our response to the Axios developer tool compromise
OpenAI confirms zero user data breach after supply chain attack. Here's what actually happened.

Why it matters
A third-party developer tool compromise exposed potential vulnerabilities in OpenAI's build pipeline. This is a critical governance and security disclosure that affects how enterprises evaluate AI vendor risk—and it matters because supply chain attacks are now a top vector for breaching AI infrastructure.
The key facts
5 to knowThird-party tool (Axios) compromised in supply chain attack
OpenAI rotated macOS code signing certificates as immediate response
Zero user data compromised according to OpenAI
Incident affects software build/distribution pipeline
Published April 9, 2026 as official disclosure
Go to the source
OpenAI Blogopenai.com
Publisher excerpt: OpenAI responds to the Axios supply chain attack by rotating macOS code signing certificates, updating apps, and confirming no user data was compromised.