Researchers used Claude to chain vulnerabilities and access OpenAI's internal GitHub in under 72 hours
Hacktron researchers chained Discourse image-upload flaw (community.openai.com) with SSO token issues to access ChatGPT and GitHub. Used Claude (Opus 5) to craft exploit; opened internal PR without exfiltration. OpenAI patched within ~14 hours; paid $6,500 bounty.
TLDR
Demonstrates LLMs accelerating real-world exploit development and highlights the irony of Claude-assisted hacking of an AI competitor. Raises questions about forum security, SSO implementations, and agentic AI safeguards. Illustrates how capable AI models compress security research cycles and challenge assumptions about AI agent containment and misuse risks.
Combined views
188
1 Source, first seen 12h ago
Researchers used Claude to chain vulnerabilities and access OpenAI's internal GitHub in under 72 hours
Hacktron researchers chained Discourse image-upload flaw (community.openai.com) with SSO token issues to access ChatGPT and GitHub. Used Claude (Opus 5) to craft exploit; opened internal PR without exfiltration. OpenAI patched within ~14 hours; paid $6,500 bounty.