Researchers reportedly used Claude to access OpenAI’s private code
The Wall Street Journal reports that an independent bug-hunting team accessed an OpenAI employee’s ChatGPT account, giving it a way to read and suggest changes to the company’s private software.
TLDR
The Wall Street Journal reports that security researchers used Anthropic’s Claude to access an OpenAI employee’s ChatGPT account and reach the company’s private software.
A researcher involved says the July 25 breach used two bugs to take over employees’ ChatGPT/Codex accounts and some unaffiliated users’ accounts, reaching connected services including Outlook, Slack and GitHub. They say the team demonstrated access with a pull request—a proposed code change—in OpenAI’s internal codebase, and that the effort took less than 72 hours.
A post relaying the Journal’s coverage says OpenAI reported that its review found only “limited reads” of private-repository metadata and code changes, with no model weights believed exposed.
Combined views
4.8M
62 Sources, first seen ago