Researchers used Anthropic's Claude to hack OpenAI systems via forum vulnerability in ~72 hours
Security firm Hacktron chained vulnerabilities in OpenAI's Discourse forum (HEIF/HEIC image processing) to gain remote code execution, access employee accounts via SSO, and reach OpenAI's internal GitHub monorepo. Claude Opus 5 developed the exploit; team received $6,500 bounty.
TLDR
Demonstrates AI accelerating offensive security research and the irony of one lab's model breaching a rival. Highlights risks for any organization and fuels debates on AI agent risks, forum/SSO hygiene, and nation-state implications. The exploit cost <$3,000 in tokens, illustrating accessibility of AI-assisted hacking.
Researchers used Anthropic's Claude to hack OpenAI systems via forum vulnerability in ~72 hours
Security firm Hacktron chained vulnerabilities in OpenAI's Discourse forum (HEIF/HEIC image processing) to gain remote code execution, access employee accounts via SSO, and reach OpenAI's internal GitHub monorepo. Claude Opus 5 developed the exploit; team received $6,500 bounty.
