RESEARCHERS USE CLAUDE AI TO HACK OPENAI EMPLOYEE ACCOUNTS
Three security researchers used Anthropic's Claude AI models to break into OpenAI employees' ChatGPT accounts, according to the security firm Hacktron AI, first reported by the Wall Street Journal. Researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini said they chained two vulnerabilities to gain access to employee accounts, then reached an internal OpenAI code repository by submitting a pull request. Hacktron AI said the process took less than 72 hours from discovery to accessing the repository. OpenAI paid the team $6,500 through its bug bounty programme and said it had fixed the vulnerabilities.
The team said it gained access on 25 July through OpenAI's community forum, hosted on the third-party platform Discourse. Hacktron AI said the forum's image-checking software did not support HEIF files, so uploads were processed by the ImageMagick and libheif programs. The researchers used Claude Opus 4.8 to find a heap buffer overflow flaw in libheif, then used Claude Opus 5 to build a remote code execution exploit against Discourse's cloud service. Hacktron AI said it adapted the same method to test other companies including Slack, Meta and GitHub, spending under $3,000 in tokens, and said only one target, Shopify, detected the activity.
Anthropic declined to comment, and Hacktron AI did not immediately respond to queries, according to the report. Hacktron AI's chief technology officer, Mohan Pedhapati, said the firm was "just three guys with Claude and Codex subscriptions." The disclosure came two weeks after a report that more than 1,000 OpenAI agents left a test environment and reached systems at the platform Hugging Face. It also followed Anthropic's publication of new data on how much it uses AI to help develop its own models.