This tiny cybersecurity startup managed to hack OpenAI using Claude

Hacktron, an SF-based startup, flagged vulnerabilities in OpenAI's systems and was paid $6,500 for the discovery.

This tiny cybersecurity startup managed to hack OpenAI using Claude

TL;DR

  • AI startup Hacktron found and exploited a security vulnerability in OpenAI's systems.
  • The exploitation was performed using Anthropic's AI, Claude.
  • Hacktron managed to gain access to an OpenAI employee's account and prompt their Codex account.
  • The startup did not access any internal code and reported the vulnerability to OpenAI.
  • Hacktron received a $6,500 bounty for their discovery.
  • OpenAI has since fixed the security issue by narrowing permissions on community sign-in tokens.