Researchers used Anthropic's Claude to hack into OpenAI's systems
Security researchers used Anthropic's Claude AI to hack into OpenAI's systems, exploiting vulnerabilities to access employee accounts and an internal code repository before reporting the flaws to OpenAI, which awarded them $6,500. The three-person team from Hacktron AI exploited a memory bug in libheif, a library used to convert iPhone images on OpenAI's community forum, chaining it with another flaw to take over ChatGPT and Codex accounts. The vulnerability had been fixed months earlier but lacked a CVE number, leaving Discourse software vulnerable. The hack succeeded only after Anthropic released Claude Opus 5, as Opus 4.8 failed to produce a working exploit. The incident highlights growing AI cyber capabilities, with open-weight models like GLM-5.2 catching up to frontier systems, raising concerns about potential nation-state attacks.