• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    AI

    Researchers reportedly used Claude to access OpenAI’s private code

    The Wall Street Journal reports that an independent bug-hunting team accessed an OpenAI employee’s ChatGPT account, giving it a way to read and suggest changes to the company’s private software.

    Miles BrundageMB
    Ethan PerezEP
    Joshua AchiamJA
    62 Sources, ,

    TLDR

    The Wall Street Journal reports that security researchers used Anthropic’s Claude to access an OpenAI employee’s ChatGPT account and reach the company’s private software.

    A researcher involved says the July 25 breach used two bugs to take over employees’ ChatGPT/Codex accounts and some unaffiliated users’ accounts, reaching connected services including Outlook, Slack and GitHub. They say the team demonstrated access with a pull request—a proposed code change—in OpenAI’s internal codebase, and that the effort took less than 72 hours.

    A post relaying the Journal’s coverage says OpenAI reported that its review found only “limited reads” of private-repository metadata and code changes, with no model weights believed exposed.

    Combined views

    4.8M

    62 Sources, first seen 20d ago

    Combined views

    4.8M

    62 Sources, first seen 20d ago

    36.2K likes
    20d ago
    first seen 20d ago
    36.2K likes1.1K comments11.9K saves4.7K reposts
    1.1K comments
    11.9K saves
    4.7K reposts

    Sentiment

    Positive37.2%62.8%Negative

    Summary

    Many accounts criticized OpenAI's security as incompetent or ironic after researchers used Claude Opus 5 to breach the company, while others saw the incident as a useful demonstration of AI-assisted vulnerability testing.

    Based on 203 sentiment-bearing replies from 180 accounts across 13 conversations.

    Sentiment

    Positive37.2%62.8%Negative

    Summary

    Many accounts criticized OpenAI's security as incompetent or ironic after researchers used Claude Opus 5 to breach the company, while others saw the incident as a useful demonstration of AI-assisted vulnerability testing.

    Based on 203 sentiment-bearing replies from 180 accounts across 13 conversations.

    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet

    62 Sources

    Gary Marcus@GaryMarcusSay it with me. “OpenAI is not good at cybersecurity.”20d
    The Wall Street Journal@WSJA bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. https://on.wsj.com/4h8vaBP20d
    MTS@MTSliveSITUATION DETECTED: Three researchers at Hacktron AI, operating under OpenAI’s bug-bounty safe harbor, used Claude Opus 5 in late July to break into an OpenAI employee’s Codex account, read the company’s private GitHub monorepo, and open a pull request as proof, per WSJ.20d
    Andrew Curran@AndrewCurran_They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.20d
    Ethan Perez@EthanJPerezRT @WSJ: A bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT a…20d
    Joshua Saxe@joshua_saxeTakeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) model weights or c) gotten access to user data; these are fair public interest questions - how many have implants in / are dwelling in the openai network as I tweet this - how pervasive is this level of softness to pentesting across all the labs and how far are the labs from the right operating point in the security and r&d friction trade space (probably pretty far it seems) - given the hacktron folks used anthropic's models to pull this off what's the real public safety ROI of anthropic's cyber guardrails; they add friction for legitimate cyber defenders (like our developers at my startup!) but it appears with a bit of work you can use them in actual breaches as happened here - as the article says, the wsj folks and @S1r1u5_ had me do neutral technical review of the kill chain here pre publication; impressive from a human angle (@HacktronAI reminds me of the best of my generation of hackers I looked up to as a kid!) but also from what the models can do; between this and the openai/hf thing, I'm emotionally in a place where I feel my world as a security person is being turned upside down in slow motion with respect to what's coming - elite persistent hacking is becoming rapidly democratized. this is coming like a freight train. we need to harden the world's code and infra as fast as possible and today's non automated methods don't stand a chance of cutting it; the world is a soft target. I continue to be unsettled but very glad I left my comfortable job at Meta to do our automated posture hardening startup20d
    Miles Brundage@Miles_BrundageRT @joshua_saxe: Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (befo…20d
    s1r1us@S1r1u5_On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵20d
    Jeffrey Ladish@JeffLadishIf they got full access to the monorepo, that means they could have downloaded OpenAI’s entire code base20d
    Yuchen Jin@Yuchenj_UWOK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours. AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.20d

    62 Sources

    Gary Marcus@GaryMarcusSay it with me. “OpenAI is not good at cybersecurity.”20d
    The Wall Street Journal@WSJA bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. https://on.wsj.com/4h8vaBP20d
    MTS@MTSliveSITUATION DETECTED: Three researchers at Hacktron AI, operating under OpenAI’s bug-bounty safe harbor, used Claude Opus 5 in late July to break into an OpenAI employee’s Codex account, read the company’s private GitHub monorepo, and open a pull request as proof, per WSJ.20d
    Andrew Curran@AndrewCurran_They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.20d
    Ethan Perez@EthanJPerezRT @WSJ: A bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT a…20d
    Joshua Saxe@joshua_saxeTakeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) model weights or c) gotten access to user data; these are fair public interest questions - how many have implants in / are dwelling in the openai network as I tweet this - how pervasive is this level of softness to pentesting across all the labs and how far are the labs from the right operating point in the security and r&d friction trade space (probably pretty far it seems) - given the hacktron folks used anthropic's models to pull this off what's the real public safety ROI of anthropic's cyber guardrails; they add friction for legitimate cyber defenders (like our developers at my startup!) but it appears with a bit of work you can use them in actual breaches as happened here - as the article says, the wsj folks and @S1r1u5_ had me do neutral technical review of the kill chain here pre publication; impressive from a human angle (@HacktronAI reminds me of the best of my generation of hackers I looked up to as a kid!) but also from what the models can do; between this and the openai/hf thing, I'm emotionally in a place where I feel my world as a security person is being turned upside down in slow motion with respect to what's coming - elite persistent hacking is becoming rapidly democratized. this is coming like a freight train. we need to harden the world's code and infra as fast as possible and today's non automated methods don't stand a chance of cutting it; the world is a soft target. I continue to be unsettled but very glad I left my comfortable job at Meta to do our automated posture hardening startup20d
    Miles Brundage@Miles_BrundageRT @joshua_saxe: Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (befo…20d
    s1r1us@S1r1u5_On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵20d
    Jeffrey Ladish@JeffLadishIf they got full access to the monorepo, that means they could have downloaded OpenAI’s entire code base20d
    Yuchen Jin@Yuchenj_UWOK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours. AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.20d