Researchers used Anthropic’s Claude to hack into OpenAI

← Back to the feed

Researchers used Anthropic’s Claude to hack into OpenAI

TechCrunch · 2 days ago

Security researchers from startup Hacktron AI used Anthropic's Claude AI model to successfully breach OpenAI's systems, discovering critical vulnerabilities that allowed them to access multiple employee ChatGPT accounts. The hack was conducted through OpenAI's official bug-bounty programme and demonstrates the dual-edged nature of modern AI technology: the same advanced models that companies rely on are now being used to expose their security weaknesses. The incident underscores growing concerns about AI safety and the vulnerability of even the world's most advanced technology companies.

Hacktron exploited a chain of two critical vulnerabilities beginning on 25 July through a flaw in Discourse, the forum software powering OpenAI's community platform, with the initial entry point being an image upload vulnerability. The flaw involved a memory bug in the libheif library used to process iPhone image formats (HEIF/HEIC), which had been patched months earlier by developers but never formally registered as a known vulnerability, leaving OpenAI's systems exposed. Remarkably, Anthropic's Opus 4.8 model initially struggled to build a working exploit, but the newly released Opus 5 succeeded within hours, highlighting how rapidly AI capabilities are advancing. OpenAI has resolved the issues and awarded Hacktron $6,500, whilst security experts warn that for just $200 per month, anyone now has access to tools powerful enough to compromise major corporations.

  • Researchers used Claude AI to exploit vulnerabilities in OpenAI's systems and access employee accounts
  • An unregistered security flaw in image-processing software provided the initial entry point
  • Claude Opus 5's superior capabilities made the exploit possible where earlier versions failed

AI Cybersecurity Research Science Technology

Read the full article at the source →