• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology

Security researchers reportedly used Claude to access an OpenAI employee’s ChatGPT account

The Wall Street Journal reports that the independent bug-hunting team gained a way to read and suggest changes to OpenAI’s private software.

Lawrence ChanLC
The Wall Street JournalTW
Andrew CurranAC
14 Sources, 20d ago, first seen 20d ago

TLDR

An independent security research team used Anthropic’s Claude to gain access to an OpenAI employee’s ChatGPT account, The Wall Street Journal reports. That access gave the team a way to read and suggest changes to the company’s private software.

Combined views

6.4M

14 Sources, first seen 20d ago

49.3K likes1.5K comments14.8K saves5K reposts

Combined views

6.4M

14 Sources, first seen 20d ago

49.3K likes1.5K comments14.8K saves5K reposts

Sentiment

Positive34.4%65.6%Negative

Summary

Negative replies focused on the low $6,500 bounty for the OpenAI hack via libheif and its irony with recent security claims, while some accounts expressed amusement at the xkcd reference or praised the disclosure.

Based on 139 sentiment-bearing replies from 125 accounts across 7 conversations.

Sentiment

Positive34.4%65.6%Negative

Summary

Negative replies focused on the low $6,500 bounty for the OpenAI hack via libheif and its irony with recent security claims, while some accounts expressed amusement at the xkcd reference or praised the disclosure.

Based on 139 sentiment-bearing replies from 125 accounts across 7 conversations.

14 Sources

Lawrence Chan@justanotherlawThis is crazy. In late July, "three guys with Claude and Codex subscriptions" were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba88320d
The Wall Street Journal@WSJA bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. https://on.wsj.com/4h8vaBP20d
Andrew Curran@AndrewCurran_They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.20d
s1r1us@S1r1u5_On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵20d
Financial Times@FTOpenAI breached by researchers using Anthropic models https://ft.trib.al/ykva0le20d
Hacktron AI@HacktronAIOn July 25, our team hacked OpenAI. It took us less than 72 hours. Two vulnerabilities chained together gave us access to ChatGPT and Codex accounts belonging to OpenAI employees. We demonstrated the impact with a harmless PR in OpenAI’s internal monorepo. The full chain: HEIF upload → libheif heap overflow → RCE → OpenAI SSO flaw → ChatGPT/Codex takeover → connected GitHub → internal PR. OpenAI fixed the SSO issue roughly 14 hours after our report. Research by @rootxharsh, @S1r1u5_ and @iamnoooob. Full technical write-up: https://hacktron.ai/blog/hacking-openai?utm_source=x&utm_medium=social-founder&utm_campaign=disclosure&utm_content=openai-launch20d
Harsh Jaiswal@rootxharshWe’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵20d
Polymarket@PolymarketBREAKING: Security researchers reportedly used Anthropic’s Claude to break into an OpenAI employee’s ChatGPT account.20d
Watcher.Guru@WatcherGuruJUST IN: OpenAI hacked by researchers using Anthropic's AI models, FT reports.20d
The Spectator Index@spectatorindexJUST IN: Cyber researchers were able to access the account of an OpenAI employee using software made by its rival Anthropic, according to Financial Times report.20d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    14 Sources

    Lawrence Chan@justanotherlawThis is crazy. In late July, "three guys with Claude and Codex subscriptions" were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days. https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba88320d
    The Wall Street Journal@WSJA bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software. https://on.wsj.com/4h8vaBP20d
    Andrew Curran@AndrewCurran_They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.20d
    s1r1us@S1r1u5_On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵20d
    Financial Times@FTOpenAI breached by researchers using Anthropic models https://ft.trib.al/ykva0le20d
    Hacktron AI@HacktronAIOn July 25, our team hacked OpenAI. It took us less than 72 hours. Two vulnerabilities chained together gave us access to ChatGPT and Codex accounts belonging to OpenAI employees. We demonstrated the impact with a harmless PR in OpenAI’s internal monorepo. The full chain: HEIF upload → libheif heap overflow → RCE → OpenAI SSO flaw → ChatGPT/Codex takeover → connected GitHub → internal PR. OpenAI fixed the SSO issue roughly 14 hours after our report. Research by @rootxharsh, @S1r1u5_ and @iamnoooob. Full technical write-up: https://hacktron.ai/blog/hacking-openai?utm_source=x&utm_medium=social-founder&utm_campaign=disclosure&utm_content=openai-launch20d
    Harsh Jaiswal@rootxharshWe’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵20d
    Polymarket@PolymarketBREAKING: Security researchers reportedly used Anthropic’s Claude to break into an OpenAI employee’s ChatGPT account.20d
    Watcher.Guru@WatcherGuruJUST IN: OpenAI hacked by researchers using Anthropic's AI models, FT reports.20d
    The Spectator Index@spectatorindexJUST IN: Cyber researchers were able to access the account of an OpenAI employee using software made by its rival Anthropic, according to Financial Times report.20d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet