Security researchers used Claude to hack OpenAI systems, accessing internal GitHub repo
A small team (Hacktron AI) used Claude (Opus 5) to exploit a Discourse forum image-processing flaw (HEIF/HEIC handling) and chain it with an SSO issue, accessing OpenAI employee ChatGPT accounts and the internal 'Monorepo' GitHub repo. They reported it via bug bounty and received $6,500.
TLDR
Exemplifies real-world AI-assisted hacking risks and demonstrates how quickly models improve at exploits. The irony of rival AI aiding a hack of OpenAI fuels safety/alignment debates and shows implications for nation-state threats amid calls for better oversight of AI capabilities.
Combined views
29.4K
1 Source, first seen 22h ago
Security researchers used Claude to hack OpenAI systems, accessing internal GitHub repo
A small team (Hacktron AI) used Claude (Opus 5) to exploit a Discourse forum image-processing flaw (HEIF/HEIC handling) and chain it with an SSO issue, accessing OpenAI employee ChatGPT accounts and the internal 'Monorepo' GitHub repo. They reported it via bug bounty and received $6,500.
TLDR
Exemplifies real-world AI-assisted hacking risks and demonstrates how quickly models improve at exploits. The irony of rival AI aiding a hack of OpenAI fuels safety/alignment debates and shows implications for nation-state threats amid calls for better oversight of AI capabilities.