• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology

Researchers reportedly used Claude to breach OpenAI accounts via a forum flaw

s0rk.net reports that Hacktron used Claude to compromise OpenAI accounts and reach a private repository in under 72 hours.

Station CatSC
s0rKS0
2 Sources, 20d ago, first seen 20d ago

TLDR

s0rk.net reports that Hacktron used Claude to compromise OpenAI accounts and reach a private repository in under 72 hours. A separate post relaying Hacktron's account says Claude Opus helped build an exploit for an HEIC image-processing flaw in OpenAI's developer forum. Overly broad single sign-on permissions then enabled access to linked ChatGPT and Codex accounts, and Codex's GitHub connection led to internal code, the post says. It adds that researchers left a proof message and stopped testing, OpenAI fixed the login issue in about 14 hours, and the bounty was $6,500. The same account puts AI-token costs for finding the flaw and writing the exploit at under $3,000.

Combined views

81

2 Sources, first seen 20d ago

1 likes1 reposts

Combined views

81

2 Sources, first seen 20d ago

1 likes1 reposts

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Featured Source

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Related

OpenAI's annualized revenue reportedly approached $50 billion at September's end, below the earlier reported $70 billion

The Financial Times, citing a person familiar with the matter, links the gap to investor comparisons with Anthropic.

OpenAI's annualized revenue reportedly neared $50 billion at the end of September, below the widely reported $70 billion
ChatGPT adds interactive answers, from charts to budget calculators

OpenAI says GPT-6 and Intelligent UI let you explore visual explanations and use budget calculators without leaving the conversation.

OpenAI and Anthropic representatives pledge faster safety incident disclosures at Australian hearing

Techmeme, citing ABC, says OpenAI Chief Strategy Officer Jason Kwon made the pledge, with Anthropic representatives making similar pledges.

2 Sources

Station Cat@bketck用 Claude 黑进 OpenAI 了。 不是电影那种黑客对黑客。 安全公司 Hacktron 说,他们让 Claude 盯着 OpenAI 开发者论坛的图片上传链路…… 论坛用 Discourse。HEIC 图(苹果相册常见格式)走 ImageMagick,底下的 libheif 有个没补上的洞。 Claude Opus 帮他们把洞做成能远程跑代码的脚本。 然后第二步才要命。 论坛支持「用 OpenAI 账号登录」。Hacktron 指出真正放大的是 SSO(单点登录)权限太大——论坛被拿下,就能接管绑定的 ChatGPT、Codex。 Codex 连着公司 GitHub。他们进了内部代码库,留了条证明消息,没再往下测。 OpenAI 大约 14 小时修了登录那条。赏金 $6500。 Hacktron 还写了句扎眼的:找洞+写 exploit(攻击脚本)花的 AI token,加起来不到 $3000。 模型会写攻击脚本了。 登录权限再松一点,社区论坛也能变成进门钥匙。20d
s0rK@sorkxx🚨 Una imagen HEIF manipulada, Claude Opus 5 y menos de 72 horas: tres investigadores lograron comprometer cuentas de empleados de OpenAI y llegar a un repositorio privado. 👀 👉 https://www.s0rk.net/2026/09/claude-hack-openai-cuentas-empleados.html #Claude #OpenAI #Ciberseguridad20d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    OpenAIHacktron

    2 Sources

    Station Cat@bketck用 Claude 黑进 OpenAI 了。 不是电影那种黑客对黑客。 安全公司 Hacktron 说,他们让 Claude 盯着 OpenAI 开发者论坛的图片上传链路…… 论坛用 Discourse。HEIC 图(苹果相册常见格式)走 ImageMagick,底下的 libheif 有个没补上的洞。 Claude Opus 帮他们把洞做成能远程跑代码的脚本。 然后第二步才要命。 论坛支持「用 OpenAI 账号登录」。Hacktron 指出真正放大的是 SSO(单点登录)权限太大——论坛被拿下,就能接管绑定的 ChatGPT、Codex。 Codex 连着公司 GitHub。他们进了内部代码库,留了条证明消息,没再往下测。 OpenAI 大约 14 小时修了登录那条。赏金 $6500。 Hacktron 还写了句扎眼的:找洞+写 exploit(攻击脚本)花的 AI token,加起来不到 $3000。 模型会写攻击脚本了。 登录权限再松一点,社区论坛也能变成进门钥匙。20d
    s0rK@sorkxx🚨 Una imagen HEIF manipulada, Claude Opus 5 y menos de 72 horas: tres investigadores lograron comprometer cuentas de empleados de OpenAI y llegar a un repositorio privado. 👀 👉 https://www.s0rk.net/2026/09/claude-hack-openai-cuentas-empleados.html #Claude #OpenAI #Ciberseguridad20d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet