Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Anthropic's Claude used by researchers to breach OpenAI systems

Security researchers utilised Anthropic's Claude to exploit vulnerabilities in OpenAI's systems, gaining access to employee accounts and an internal code repository.

  • A three-person team from Hacktron AI used Anthropic's Claude Opus 5 to exploit two critical vulnerabilities in OpenAI's systems.
  • The breach allowed access to multiple OpenAI employee ChatGPT accounts and the company's software, including a GitHub organisation.
  • OpenAI awarded Hacktron AI $6,500 for reporting the flaws, which OpenAI states have now been resolved.

Independent security researchers from Hacktron AI used Anthropic's Claude Opus 5 to breach OpenAI's defences, according to a report by The Wall Street Journal. The three-person team exploited two critical vulnerabilities as part of an OpenAI bug-bounty program.

The researchers gained access to multiple OpenAI employee ChatGPT accounts and subsequently entered the company's software, including a GitHub organisation linked to an employee's Codex account. The initial entry point was a flaw in Discourse, the third-party software powering OpenAI's community forum, specifically related to HEIF/HEIC image file processing.

Hacktron AI reported their findings to OpenAI, which has since resolved the issues and awarded the startup $6,500. The researchers noted that an earlier version, Claude Opus 4.8, struggled to create a working exploit, but Opus 5 succeeded within hours of its release.

Matt Fredrikson, CEO of Gray Swan, commented that such tools, available for around $200 a month, can enable hacking into companies like OpenAI. Hacktron founder Mohan Pedhapati stated that AI is reducing the expertise needed for exploit development, potentially shortening work that once took months to days.

Why this matters: The incident highlights the increasing capability of AI models in cybersecurity, demonstrating how off-the-shelf AI technology can be used to find vulnerabilities in advanced companies' infrastructure.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.