Security researchers used Claude to hack OpenAI systems in ethical bug bounty disclosure
Hacktron AI researchers chained vulnerabilities in OpenAI's Discourse forum using Claude Opus 5 to develop exploits in under 72 hours (~$3k in tokens), gaining access to employee accounts and internal GitHub repos. OpenAI paid $6,500 bounty and fixed issues.
TLDR
The incident demonstrates how AI tools accelerate both offense and defense in cybersecurity and highlights frontier model security challenges. The low cost and speed raise concerns about scaling threats from less-resourced actors, and it underscores inter-lab competition dynamics.
Combined views
—
2 Sources, first seen 5h ago
Security researchers used Claude to hack OpenAI systems in ethical bug bounty disclosure
Hacktron AI researchers chained vulnerabilities in OpenAI's Discourse forum using Claude Opus 5 to develop exploits in under 72 hours (~$3k in tokens), gaining access to employee accounts and internal GitHub repos. OpenAI paid $6,500 bounty and fixed issues.
TLDR
The incident demonstrates how AI tools accelerate both offense and defense in cybersecurity and highlights frontier model security challenges. The low cost and speed raise concerns about scaling threats from less-resourced actors, and it underscores inter-lab competition dynamics.