← Latest briefing

Technology

Security researchers use Anthropic's Claude to exploit OpenAI system vulnerabilities

Cybersecurity startup Hacktron reported security flaws to OpenAI and received a $6,500 bug bounty.

The short version

  • Security researchers at startup Hacktron used Anthropic's Claude AI models to compromise OpenAI employee accounts and enter internal systems.[Business Insider · The Verge · TechCrunch]
  • The team exploited flaws in OpenAI's community forum software to access ChatGPT and Codex accounts.[Business Insider · TechCrunch]
  • Hacktron reported the vulnerabilities directly to OpenAI, which paid the researchers a $6,500 bounty.[Business Insider]
  • OpenAI said it revoked affected tokens and sessions while narrowing sign-in permissions to resolve the issue.[Business Insider]

Key facts

  • Hacktron is a San Francisco-based AI cybersecurity startup with fewer than 10 employees.[Business Insider]
  • The research team gained access via vulnerabilities in the third-party Discourse software powering OpenAI's community forum.[The Verge · TechCrunch]
  • The researchers used Anthropic's Claude Opus models under a specialized program for cybersecurity research to create the exploit.[Business Insider · The Verge · TechCrunch]
  • Hacktron prompted an employee's Codex account to suggest code repository changes but reported stopping before viewing internal code.[Business Insider · The Verge]
  • OpenAI awarded Hacktron a $6,500 bug bounty and revoked affected sign-in tokens and sessions.[Business Insider · TechCrunch]

What remains uncertain

  • Reports vary on whether the researchers accessed OpenAI internal code, though Hacktron stated its team stopped short of viewing internal source code.[Business Insider · TechCrunch]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.