Researchers used Anthropic's Claude to breach OpenAI systems in under 72 hours
White-hat team chained a Discourse HEIF vulnerability with SSO issues to access employee ChatGPT accounts and internal GitHub monorepo, demonstrating control via harmless pull request. Claude Opus 5 succeeded at ~$3k in tokens. OpenAI paid $6,500 bounty.
TLDR
Demonstrates how newer AI models accelerate both offensive and defensive cyber capabilities, compressing months of work into days or hours. Highlights supply-chain and SSO risks for AI tools and double-edged nature of advancing agentic systems, part of broader 'HEIF Heist' research affecting multiple platforms.
Researchers used Anthropic's Claude to breach OpenAI systems in under 72 hours
White-hat team chained a Discourse HEIF vulnerability with SSO issues to access employee ChatGPT accounts and internal GitHub monorepo, demonstrating control via harmless pull request. Claude Opus 5 succeeded at ~$3k in tokens. OpenAI paid $6,500 bounty.
