Researchers use Claude to breach OpenAI's codebase, earn $6,500 bounty
Researchers used Anthropic's Claude to breach OpenAI's private codebase, exploiting authentication vulnerabilities to access employee accounts and internal systems. OpenAI paid a $6,500 bug bounty after the issue was fixed. Hacktron, a cybersecurity startup, compromised multiple OpenAI employee ChatGPT accounts on July 25, reaching private GitHub environments where they read code and proposed changes. The team reported the flaw to OpenAI and Discourse, working with them on patches. The attack exploited a single sign-on misconfiguration and a remote-code-execution vulnerability in OpenAI's community forum, potentially exposing integrations like GitHub, Slack, and email. OpenAI confirmed the problem was resolved, highlighting security risks beyond AI models themselves.