This tiny cybersecurity startup managed to hack OpenAI using Claude
Hacktron, an SF-based startup, flagged vulnerabilities in OpenAI's systems and was paid $6,500 for the discovery.
TL;DR
- AI startup Hacktron found and exploited a security vulnerability in OpenAI's systems.
- The exploitation was performed using Anthropic's AI, Claude.
- Hacktron managed to gain access to an OpenAI employee's account and prompt their Codex account.
- The startup did not access any internal code and reported the vulnerability to OpenAI.
- Hacktron received a $6,500 bounty for their discovery.
- OpenAI has since fixed the security issue by narrowing permissions on community sign-in tokens.