Researchers reportedly used Claude Opus to exploit OpenAI forum flaws
A user says three researchers spent less than $3,000 on tokens to gain privileged access in under 72 hours, then received a $6,500 bounty from OpenAI.
TLDR
A user describes a Claude Opus-assisted exploit that began with a corrupted HEIF image upload on OpenAI's Discourse-based community forum. The post says a memory bug allowed code execution on the server, and a second flaw in "Login with OpenAI" enabled takeovers of ChatGPT and Codex accounts belonging to people who logged into the forum, including employees. According to the account, the researchers demonstrated access by opening a pull request in a private OpenAI code repository, then stopped and reported the issues. The user says OpenAI promptly patched the flaws and awarded a $6,500 bounty.