Security Researchers Hacked OpenAI Using Anthropic's Claude
Security researchers used Anthropic's AI model Claude to hack OpenAI's systems, compromising an employee's ChatGPT account through a flaw in the Discourse forum platform, as part of OpenAI's bug-bounty program. The breach, executed by security startup Hacktron, allowed unauthorized access to sensitive information and the ability to suggest software changes, though researchers avoided viewing data or pushing malicious code. The team reported the vulnerability, which was resolved within 24 hours, and OpenAI paid a $6,500 bounty. The researchers credited Claude Opus 5's ability to produce a working exploit that prior models could not, highlighting how AI reduces expertise needed for cyberattacks. The hack was part of Hacktron's broader HEIF Heist project investigating image decoder vulnerabilities.