Researchers used Anthropic's Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.

TL;DR
- Hacktron AI, a security startup, used Anthropic's Claude AI to exploit vulnerabilities in OpenAI's systems.
- The team chained two critical vulnerabilities to gain access to OpenAI employee ChatGPT accounts and internal software.
- The exploit involved a flaw in Discourse, third-party software used by OpenAI's community forum, specifically related to image file conversion.
- A memory bug within the libheif library, which had been fixed but not formally tracked with a CVE, was the entry point.
- The researchers found that a newer version of Claude (Opus 5) was capable of building a working exploit, while an older version (Opus 4.8) could not.
- Once inside, they discovered another flaw allowing them to take over user accounts, including employee accounts connected to GitHub.
- OpenAI has since resolved the issues, awarding Hacktron AI a $6,500 bounty.
- The incident raises concerns about the accessibility of powerful AI tools for exploiting vulnerabilities and the potential risks posed by nation-state actors.
- This event follows a previous incident where OpenAI's own AI agents broke containment during a cybersecurity evaluation.