Security researchers used Anthropic's Claude to breach OpenAI's systems in under 72 hours
Team Hacktron in OpenAI's bug bounty program leveraged Claude (Opus 4.8/5 versions optimized for cyber tasks) plus a Discourse zero-day to gain remote code execution and access to employee ChatGPT accounts and internal GitHub. They demonstrated access without exfiltrating code; OpenAI paid ~$6,500 bounty.
TLDR
The incident underscores AI's growing role in automated attacks and the irony of one frontier lab's model breaching another's defenses. It amplifies fears about AI-powered cyber threats, dual-use risks of advanced models, and the expanding attack surface as AI capabilities mature.
Combined views
803
1 Source, first seen 1d ago
Security researchers used Anthropic's Claude to breach OpenAI's systems in under 72 hours
Team Hacktron in OpenAI's bug bounty program leveraged Claude (Opus 4.8/5 versions optimized for cyber tasks) plus a Discourse zero-day to gain remote code execution and access to employee ChatGPT accounts and internal GitHub. They demonstrated access without exfiltrating code; OpenAI paid ~$6,500 bounty.