Back
Researchers Used Anthropic's Claude to Breach OpenAI Employee Accounts
SiTech AI Team3 წთ. საკითხავი

Researchers Used Anthropic's Claude to Breach OpenAI Employee Accounts

Researchers at Hacktron AI used Anthropic's Claude to exploit a libheif image bug in OpenAI's Discourse forum and an SSO flaw to reach employee ChatGPT and Codex accounts. OpenAI fixed the issues and paid a $6,500 bounty.

Researchers at the startup Hacktron AI used Anthropic's Claude to build an exploit chain that let them take over multiple OpenAI employee accounts through a flaw in the company's community forum, which runs on Discourse. The three-person team reported the findings through OpenAI's bug bounty program and received a $6,500 award; OpenAI says it has fixed the issues.

From an image upload to internal repositories

According to Hacktron's account, the entry point was a mundane image upload. When users posted HEIF or HEIC photos — the format iPhones use by default — on community.openai.com, the forum software converted them to standard JPEGs, passing the files from ImageMagick to a library called libheif.

A heap buffer overflow in libheif let a specially crafted image hijack the server. The flaw had been fixed upstream earlier, but the change was never flagged as a security fix, so it got no CVE number and Debian systems still shipped the vulnerable version. Once inside the forum, the team chained a second flaw in OpenAI's single sign-on system to take over employee ChatGPT and Codex accounts.

Redacted pull request demonstrating access to OpenAI's internal monorepo

From there, the researchers reached an employee whose Codex was connected to OpenAI's GitHub organization. To prove the impact without reading internal code, they used that Codex account to open a pull request in OpenAI's internal monorepo. The chain took less than 72 hours.

Claude's role

Claude did much of the heavy lifting, the team says. A cybersecurity-focused version of Opus 4.8 "struggled across several sessions to produce a working exploit," Hacktron wrote. That changed within hours of Claude Opus 5's release: the new model produced a working ARM64 exploit for a local Mac in about three hours, then ported it to x86-64.

"AI is reducing the amount of scarce expertise needed to develop exploits," Hacktron founder Mohan Pedhapati wrote. "Work that once took months can now take days."

Disclosure and fallout

The attack took place on July 25, and the case became public in mid-September. OpenAI confirmed the fix roughly 14 hours after Hacktron's initial submission, and on September 1 marked the report resolved with a $6,500 bounty. The company noted that forum testing was excluded from its program and that the award recognized the OpenAI-side finding; Discourse fixed its side by July 27.

The escalation flaw was not specific to Discourse: any OpenAI service using the same single sign-on flow could have led to the same access. "For $200 a month, anyone can use these tools and hack into a company like OpenAI," Matt Fredrikson, CEO of the security firm Gray Swan, told TechCrunch. "If it can happen to them, it could happen to anyone."

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.