Technology
Security researchers use Anthropic's Claude to exploit OpenAI system vulnerabilities
Cybersecurity startup Hacktron reported security flaws to OpenAI and received a $6,500 bug bounty.
The short version
- Security researchers at startup Hacktron used Anthropic's Claude AI models to compromise OpenAI employee accounts and enter internal systems.[Business Insider · The Verge · TechCrunch]
- The team exploited flaws in OpenAI's community forum software to access ChatGPT and Codex accounts.[Business Insider · TechCrunch]
- Hacktron reported the vulnerabilities directly to OpenAI, which paid the researchers a $6,500 bounty.[Business Insider]
- OpenAI said it revoked affected tokens and sessions while narrowing sign-in permissions to resolve the issue.[Business Insider]
Key facts
- Hacktron is a San Francisco-based AI cybersecurity startup with fewer than 10 employees.[Business Insider]
- The research team gained access via vulnerabilities in the third-party Discourse software powering OpenAI's community forum.[The Verge · TechCrunch]
- The researchers used Anthropic's Claude Opus models under a specialized program for cybersecurity research to create the exploit.[Business Insider · The Verge · TechCrunch]
- Hacktron prompted an employee's Codex account to suggest code repository changes but reported stopping before viewing internal code.[Business Insider · The Verge]
- OpenAI awarded Hacktron a $6,500 bug bounty and revoked affected sign-in tokens and sessions.[Business Insider · TechCrunch]
What remains uncertain
- Reports vary on whether the researchers accessed OpenAI internal code, though Hacktron stated its team stopped short of viewing internal source code.[Business Insider · TechCrunch]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.