Hacktron AI researchers used Claude to exploit OpenAI vulnerabilities, earning $6,500 bug bounty
Hacktron AI chained vulnerabilities including a libheif image library issue and sign-in token misconfiguration to access OpenAI employee accounts and internal GitHub repository in under 72 hours using Claude. OpenAI patched issues within 14 hours and paid the bounty.
TLDR
The incident demonstrates rapid progress in AI-assisted offensive security capabilities and raises questions about frontier AI lab vulnerabilities and agentic risks. It highlights how frontier models can be leveraged for exploitation while illustrating the responsible disclosure and bug bounty process in action. The story underscores growing concerns about AI agents' hacking capabilities and AI safety implications.
Combined views
17.7K
1 Source, first seen 1h ago
Hacktron AI researchers used Claude to exploit OpenAI vulnerabilities, earning $6,500 bug bounty
Hacktron AI chained vulnerabilities including a libheif image library issue and sign-in token misconfiguration to access OpenAI employee accounts and internal GitHub repository in under 72 hours using Claude. OpenAI patched issues within 14 hours and paid the bounty.
TLDR
The incident demonstrates rapid progress in AI-assisted offensive security capabilities and raises questions about frontier AI lab vulnerabilities and agentic risks. It highlights how frontier models can be leveraged for exploitation while illustrating the responsible disclosure and bug bounty process in action. The story underscores growing concerns about AI agents' hacking capabilities and AI safety implications.