White-hat researchers used Anthropic's Claude to exploit OpenAI system vulnerabilities
Security researchers (Hacktron AI) used Claude Opus 5 in under 72 hours for ~$3k to exploit vulnerabilities in OpenAI's Discourse forum. They leveraged an unpatched libheif flaw and SSO issue, gaining access to employee accounts and an internal GitHub monorepo. OpenAI paid a $6,500 bounty.
TLDR
The exploit demonstrates how advanced AI coding tools dramatically lower barriers for sophisticated attacks by small teams. It raises concerns about AI accelerating exploit development and highlights inter-lab dynamics in the competitive frontier AI landscape while showcasing responsible disclosure.
Combined views
35
1 Source, first seen 2h ago
White-hat researchers used Anthropic's Claude to exploit OpenAI system vulnerabilities
Security researchers (Hacktron AI) used Claude Opus 5 in under 72 hours for ~$3k to exploit vulnerabilities in OpenAI's Discourse forum. They leveraged an unpatched libheif flaw and SSO issue, gaining access to employee accounts and an internal GitHub monorepo. OpenAI paid a $6,500 bounty.
TLDR
The exploit demonstrates how advanced AI coding tools dramatically lower barriers for sophisticated attacks by small teams. It raises concerns about AI accelerating exploit development and highlights inter-lab dynamics in the competitive frontier AI landscape while showcasing responsible disclosure.