Claude model helps researchers breach OpenAI employee accounts

techno.nv.ua (Ukrainian)

Researchers from startup Hacktron AI combined two critical vulnerabilities to access several ChatGPT accounts belonging to OpenAI employees, earning a $6,500 bounty. The attack began July 25 via Discourse, OpenAI's community forum software, which converted iPhone HEIC photos using ImageMagick and libheif. A crafted file triggered a memory error, allowing server takeover. Hacktron initially used Claude Opus 4.8, but succeeded only after Opus 5's release, completing the exploit within hours. The team then exploited another flaw to seize an OpenAI employee's account linked to company GitHub. Discourse fixed the issue July 27, and OpenAI has since patched the problems.


With a significance score of 3.5, this news ranks in the top 8.9% of today's 32136 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: