Skip Navigation
!tech@coves.social

Hacktron researchers used Anthropic’s Claude models to chain vulnerabilities in OpenAI’s public community forum and sign-in system, gaining access to several OpenAI employees’ ChatGPT and Codex accounts and a private software repository. The work took place under OpenAI’s bug-bounty program, and the researchers said they neither downloaded nor inspected proprietary source code. They demonstrated repository access by submitting a harmless pull request before ending the test [securityweek.com][theguardian.com][androidheadlines.com][techcrunch.com]. The initial weakness involved HEIC and HEIF image uploads processed by Discourse through ImageMagick and the libheif library, while a separate single sign-on flaw allowed forum session tokens to remain valid across internal OpenAI tools. Hacktron said Claude Opus 4.8 failed to produce a working exploit, but Opus 5 generated a functional payload within hours of its release. OpenAI said it restricted the permissions of community sign-in tokens and revoked affected tokens and sessions; the company paid Hacktron a $6,500 bounty [securityweek.com][androidheadlines.com][cbsnews.com]. Highlights: • Exploit development: Hacktron said its three researchers moved from initial discovery to repository access in less than 72 hours. Agents performed work that would have taken days, while the researchers spent only a few hours hands-on [cbsnews.com][asiae.co.kr]. • Program scope: The researchers reported the OpenAI-side vulnerability through the company’s bug-bounty program, while testing of the third-party forum software fell outside the program’s scope [tribune.com.pk]. • Patch response: Discourse fixed the image-processing issue on July 25, while OpenAI fixed its identity-side weakness about 14 hours after notification [cnyes.com][cbsnews.com]. Perspectives: Hacktron AI: The three lead researchers were Harsh Jaiswal, Mohan Pedhapati and Rahul Maini [pcmag.com]. (PCMag) Matt Fredrikson, Gray Swan CEO: Fredrikson said a relatively inexpensive AI-assisted operation could threaten companies with strong cybersecurity practices [techcrunch.com]. (TechCrunch) "We thank the researchers for contacting us and sharing their findings" — AFP via El Financiero Costa Rica Sources:AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code - securityweek.com • OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot - theguardian.com • Security Researchers Use Anthropic's Claude Opus 5 to Hack OpenAI in Under 72 Hours - androidheadlines.com • Security researchers used Claude to hack into OpenAI and got paid for it - digitaltrends.com • Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack - tomshardware.com • Researchers used Claude to hack OpenAI - arstechnica.com • Security Researchers Hacked OpenAI Using Anthropic's Claude - pcmag.com • Security researchers used Claude to help them hack into OpenAI - theverge.com • OpenAI fixes flaw after Claude helps researchers reach internal code - betanews.com • Researchers used Claude to breach OpenAI's internal systems - techxplore.com • Three researchers used Claude to reach OpenAI’s internal code. OpenAI paid $6,500 and closed the hole in 14 hours. - thenextweb.com • Three Guys Using Anthropic’s Claude Hacked Into OpenAI And Accessed Its Source Code For $6,500 Reward – Fortune - digitechbytes.com • Researchers used Claude to hack OpenAI employees' ChatGPT accounts - theregister.com • Researchers used Claude to breach OpenAI’s internal systems - alarabiya.net • Researchers used Anthropic’s Claude to hack into OpenAI - techcrunch.com • Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours - cryptoslate.com • Anthropic's Claude helped cybersecurity researchers breach OpenAI: report - tribune.com.pk • Hackers utilizaron Claude de Anthropic para entrar en OpenAI - elmundo.es • Un grupo de investigadores logra hackear OpenAI utilizando Claude - eleconomista.com.mx • Χάκερ χρησιμοποίησαν το Claude της Anthropic για να εισβάλουν στην OpenAI - tovima.gr • Researchers used Anthropic’s Claude to breach OpenAI systems - eastleighvoice.co.ke • Ethische hackers breken met Claude in op systemen van OpenAI - tweakers.net • OpenAI hack: How 3 Indian-origin researchers used Anthropic’s Claude to access employee accounts - indianexpress.com • Actualité : Trois hackers ont utilisé Claude pour pirater OpenAI en 72 heures, et ils n'ont eu besoin que d'un abonnement - lesnumeriques.com • Un equipo de investigadores logra acceder a algoritmos secretos de OpenAI usando la IA de Anthropic - eldiario.es • OpenAI breached by researchers using Anthropic models - ft.com • Investigadores usan IA de Anthropic para vulnerar cuentas de empleados en OpenAI - elfinancierocr.com • Is AI Making Cyberattacks Easier? Researchers Say They Breached OpenAI Systems Using Claude - news18.com • Researchers Ethically Hack OpenAI Using Anthropic’s Claude, Win $6,500 Bounty - beijingtimes.com • 敵手AI變駭客工具!資安團隊用Anthropic模型攻破OpenAI 拿走6500美元賞金 - cnyes.com • Researchers report using Anthropic's Claude to hack OpenAI's ChatGPT - cbsnews.com • Des chercheurs ont piraté OpenAI en utilisant une IA d'Anthropic - bluewin.ch • Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours - gizmodo.com • OpenAI'daki güvenlik açığı, Claude ile keşfedildi - cumhuriyet.com.tr • Hacking OpenAI - reddit.com • AI security experts say they used Claude to hack ChatGPT - cbsnews.com • Хакеры взломали OpenAI с помощью моделей Claude - habr.com • Hackade OpenAI – med värsta rivalen Anthropics verktyg - breakit.se • It-sikkerhedsfolk brød ind i OpenAI's systemer ved hjælp af Anthropics Claude: Her er fremgangsmåden - computerworld.dk • Claude Hacks ChatGPT: A breach for less than $3,000 - albawaba.com • Hackers breached OpenAI, adding to fever pitch of security and safety concerns - allsides.com • 클로드 활용해 오픈AI 해킹 성공…72시간도 안 걸렸다 - mbn.co.kr • Des chercheurs ont piraté OpenAI en utilisant une IA d’Anthropic - 20min.ch • "클로드로 챗GPT 뚫었다"…시스템 침투까지 72시간 - asiae.co.kr • OpenAI piraté avec succès par le chatbot d’Anthropic lors d’un exercice de sécurité - liberation.fr • IA : des chercheurs ont piraté OpenAI en utilisant un modèle d’Anthropic - leparisien.fr • Investigadores usan IA de Anthropic para acceder al código interno de OpenAI y revelar dos fallas de seguridad - elperiodista.cl --- 📰 Story aggregated by Kagi News

Comments