Researchers reportedly used Claude to breach OpenAI accounts via a forum flaw
s0rk.net reports that Hacktron used Claude to compromise OpenAI accounts and reach a private repository in under 72 hours.
TLDR
s0rk.net reports that Hacktron used Claude to compromise OpenAI accounts and reach a private repository in under 72 hours. A separate post relaying Hacktron's account says Claude Opus helped build an exploit for an HEIC image-processing flaw in OpenAI's developer forum. Overly broad single sign-on permissions then enabled access to linked ChatGPT and Codex accounts, and Codex's GitHub connection led to internal code, the post says. It adds that researchers left a proof message and stopped testing, OpenAI fixed the login issue in about 14 hours, and the bounty was $6,500. The same account puts AI-token costs for finding the flaw and writing the exploit at under $3,000.
Combined views
81
2 Sources, first seen ago
