Hackers Exploit Claude to Breach OpenAI in Under 72 Hours

A trio of independent researchers named Hacktron used Anthropic’s Claude AI (Opus 4.8 and then Opus 5) to break into OpenAI systems by exploiting a Discourse image-upload bug and an OpenAI SSO flaw. They accessed an internal OpenAI discussion forum containing employee authentication tokens, potentially enabling further access to ChatGPT, Codex, Outlook, Slack, GitHub, and more. They proved their presence with a pull request to OpenAI’s internal codebase. The operation took place within 72 hours of discovery, and the researchers were paid $6,500 through OpenAI’s bug bounty program, highlighting how even AI builders can be vulnerable to sophisticated, human-guided exploits.
- Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours Gizmodo
- Exclusive | Hackers Used Anthropic’s Claude to Break Into OpenAI WSJ
- AI cybersecurity risks explode as Claude used to break into ChatGPT Semafor
- OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot The Guardian
- Hackers breached OpenAI, adding to fever pitch of security and safety concerns NBC News
Reading Insights
0
11
17 min
vs 18 min read
97%
3,585 → 100 words
Want the full story? Read the original article
Read on Gizmodo