Security researchers used Claude to hack OpenAI systems in bug bounty program
Hacktron AI researchers chained a Discourse vulnerability with token misconfiguration to access employee accounts and internal GitHub. Exploit developed in under 72 hours for under $3,000; Claude Opus 5 succeeded where Opus 4.8 struggled. Researchers earned $6,500 bounty.
TLDR
Demonstrates AI's emerging role in offensive cybersecurity—generating working exploits in hours—while exposing vulnerabilities at leading labs. Fuels debates on AI as dual-use tool and threat, model capability competition, and need for stronger defenses. Links to broader AI safety concerns and agent autonomy risks.
Combined views
68.2K
1 Source, first seen 4h ago
Security researchers used Claude to hack OpenAI systems in bug bounty program
Hacktron AI researchers chained a Discourse vulnerability with token misconfiguration to access employee accounts and internal GitHub. Exploit developed in under 72 hours for under $3,000; Claude Opus 5 succeeded where Opus 4.8 struggled. Researchers earned $6,500 bounty.
TLDR
Demonstrates AI's emerging role in offensive cybersecurity—generating working exploits in hours—while exposing vulnerabilities at leading labs. Fuels debates on AI as dual-use tool and threat, model capability competition, and need for stronger defenses. Links to broader AI safety concerns and agent autonomy risks.