Hackers Used Claude to Breach OpenAI in Under 72 Hours

gizmodo.com

Three cybersecurity researchers using the alias Hacktron breached OpenAI employee accounts in July, exploiting vulnerabilities with AI assistance from Anthropic's Claude Opus 5. The hack exposed sensitive internal systems, though the team acted under OpenAI's bug bounty program and was paid $6,500. The breach began with a flaw in Discourse, OpenAI's internal discussion platform, discovered two days prior. Using Claude Opus 5, the researchers accessed authentication tokens from an internal forum, enabling entry into ChatGPT and Codex accounts, with potential reach to GitHub, Slack, and emails. They proved access via a pull request without retrieving data. The incident highlights growing AI-enabled cyber risks, as future models may accelerate hacking capabilities. OpenAI and Discourse patched the vulnerabilities, while Anthropic CEO Dario Amodei has urged a slowdown in AI development to address potential rogue agent threats.


With a significance score of 3.4, this news ranks in the top 9.5% of today's 32136 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: