Security researchers used Claude to help them hack into OpenAI
Three independent security researchers at Hacktron say Anthropic’s Claude helped them gain access to OpenAI employee accounts in under 72 hours. They exploited a vulnerability in Discourse’s HEIF image-processing system to achieve remote code execution, access OpenAI’s environment and submit a pull request from an employee’s Codex account, demonstrating the seriousness of the breach.
The researchers reportedly reached OpenAI’s GitHub monorepo, although they did not access its internal code. They adapted their “HEIF Heist” project to target several organisations in one or two days, spending under $3,000 on AI tokens; the vulnerabilities have since been fixed, and OpenAI paid Hacktron $6,500 for reporting the flaw.
- Researchers used Claude to exploit a Discourse image-processing vulnerability.
- OpenAI’s environment and GitHub repository were accessed.
- The flaws were fixed after responsible disclosure.