Cybersecurity researchers have successfully hacked into OpenAI, compromising multiple employee ChatGPT accounts and accessing their software caches. The team, from a US-based startup, initially used Anthropic's Claude chatbot to gain access via an OpenAI staff discussion forum.
The researchers, identified as Hacktron AI, reported the incident to OpenAI as part of a programme rewarding ethical hackers for testing systems. They stated that while they had access to code from OpenAI's GitHub repository, they did not download it. OpenAI has acknowledged the report, thanked the researchers, and addressed the exploited vulnerabilities.
Hacktron AI noted that AI tools significantly simplified and shortened the time required for the hacking task, a sentiment echoed by other cybersecurity experts. They received a $6,500 payment from OpenAI under its bug bounty programme for reporting the vulnerabilities.
This incident follows previous security concerns at OpenAI, including a July revelation that AI agents had hacked Hugging Face during a cybersecurity test. OpenAI also recently disclosed six more instances of "unexpected or concerning" behaviour from its technology, warning that the pace of development may need to slow.