White-hat researchers used Anthropic's Claude to breach OpenAI's internal systems in under 72 hours
Security researchers (Hacktron AI) chained vulnerabilities in OpenAI's Discourse forum and SSO/session tokens using Claude Opus 5, gaining access to employee accounts and OpenAI's internal GitHub monorepo. They reported findings and received a $6,500 bounty.
TLDR
Highlights how advanced models accelerate exploit development and enable complex attack chains. Raises questions about using rival AIs for red-teaming or offensive purposes. Illustrates the irony of one lab's model aiding breach of another and ties into broader wave of AI-related security incidents.
White-hat researchers used Anthropic's Claude to breach OpenAI's internal systems in under 72 hours
Security researchers (Hacktron AI) chained vulnerabilities in OpenAI's Discourse forum and SSO/session tokens using Claude Opus 5, gaining access to employee accounts and OpenAI's internal GitHub monorepo. They reported findings and received a $6,500 bounty.