ChatGPT Account Access

Hackers Used Claude to Break Into OpenAI Systems

Claude, OpenAI, Hacktron AI, Claude models used in OpenAI security breach, hackers used Claude to access OpenAI systems
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Thrive Studios ID /shutterstock.com

Security researchers at Hacktron AI used Anthropic’s Claude models to chain two vulnerabilities and gain access to OpenAI’s internal systems.

A team of security researchers from startup Hacktron AI chained two vulnerabilities with the help of Anthropic’s Claude models to gain access to OpenAI’s internal systems, according to a report by The Wall Street Journal. The researchers involved were Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini.

Ad

Two Vulnerabilities Chained Together

The researchers combined a heap overflow flaw in the image decoder of Discourse, the forum software OpenAI uses for its community platform, with a separate vulnerability in the single sign-on (SSO) process.

To develop the exploit, the researchers used Claude models, including the recently released Claude Opus 5, according to VentureBeat. The models were initially run in an automated testing loop against a test instance before the resulting script was deployed against OpenAI’s actual forum.

Access to ChatGPT Account and Internal Repository

The chained vulnerability gave the researchers access to an OpenAI employee’s ChatGPT account as well as the internal openai/openai code repository on GitHub.

Ad

Rather than further investigating the systems they could access, the researchers used Codex, the programming assistant linked to the account, to create a harmless pull request in the internal repository. Their goal was simply to demonstrate that the account access extended into OpenAI’s internal development systems.

According to the researchers, they spent less than $3,000 USD on the AI tokens used during the investigation.

Disclosure and Bug Bounty

The researchers reported the vulnerabilities to both Discourse and OpenAI.

“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch. We appreciate their attention to detail and fast resolution of this issue. OpenAI also paid us a $6,500 bounty.”

“Discourse received the report on a Saturday, replied on Sunday, and had a fix by Monday (kudos for speed).”

Hacktron AI security researchers

The report was submitted through OpenAI’s Bugcrowd program on July 25. Although investigating the underlying Discourse instance was outside the scope of OpenAI’s official bug bounty program, the researchers still received the reported reward.

The incident is the latest in a series of similar reports in recent weeks. OpenAI previously disclosed that one of its own AI agents escaped an isolated test environment during an internal test and compromised the Hugging Face platform.

Shortly afterward, Anthropic also reported that its Claude models had escaped their designated test environments during security testing and gained unauthorized access to the systems of three real-world organizations.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel