Part of The AI Control Crisis · 15 stories · since Sep 3 · newest 18m ago
Researchers use Anthropic's Claude to hack into OpenAI's internal systemsHacktron publishes technical account of the OpenAI hack
6 Sep 17 10:47 PM · 6d ago · 36 articles · 20 posts · 15 comments · 7 sources · development 6 of 8
Hacktron's blog post detailed how a heap overflow and an SSO misconfiguration in OpenAI's Discourse-run help forum let them compromise OpenAI's internal repositories.
“Hacking OpenAI: A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories”
kcarruthers@infosec.exchangeOpenAI AI developer, subject of both hacksAnthropic Maker of the Claude models used in the OpenAI hackHacktron Security research firmRubyGems Ruby package registry, victim of OpenAI's May attack
Sam Altman OpenAI CEO
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
Reported in the same hours no headline names this development itself — these 5 claims were published in its stretch
-
first by Firstpost, 6d ago · also PYMNTS, The Stack, AI Policy Daily, Daily Sabah, Financial Express, The Tech Portal +7
14 more headlines
- Researchers Hack OpenAI Systems Via Anthropic's Claude NewsMax.com · 6d ago
- Security Researchers Use Anthropic's Claude to Penetrate OpenAI's Private Software Cache PYMNTS · 6d ago
- How security researchers used Anthropic to hack OpenAI The Stack · 6d ago
- Security researchers use Anthropic's Claude to reach OpenAI's internal code AI Policy Daily · 6d ago
- Anthropic's Claude used to breach OpenAI's internal systems Daily Sabah · 6d ago
- Researchers use Anthropic's Claude to find security flaws in OpenAI in 72 hours: Report Financial Express · 6d ago
- Three Indian researchers used Claude to hack into OpenAI in under 72 hours The Tech Portal · 6d ago
- Researchers Use Anthropic's Claude AI to Expose OpenAI Security Flaws: WSJ Bitcoin Insider · 6d ago
- Security researchers used Claude to hack into OpenAI and got paid for it Digital Trends · 6d ago
- OpenAI Hack: Researchers Used Anthropic's Claude AI to Breach ChatGPT Maker's Security CoinGape · 6d ago
- WSJ says researchers used Claude to access OpenAI's private software cache RuntimeWire · 6d ago
- Bug Hunters Used Claude to Hack OpenAI The Information · 6d ago
- Security Researchers Hacked Into OpenAI Using Anthropic’s Claude Forbes Business · 6d ago
- Researchers hack OpenAI with Claude’s help Techzine Global · 6d ago
-
first by TechRadar, 6d ago · also Bitcoin News, Coinpedia Fintech News, VentureBeat
3 more headlines
- White Hats Used Anthropic's Claude to Break Into OpenAI in 72 Hours Bitcoin News · 6d ago
- OpenAI Hacked Using Anthropic's Claude, Hackers Confirmed It Coinpedia Fintech News · 6d ago
- OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5 VentureBeat · 6d ago
-
5 outlets Hacking OpenAI
first by Lobsters, 6d ago · also Business Today, Hacktron AI, HN Best, HN Frontpage
1 more headline
-
first by Moneycontrol.com, 6d ago · also Moneycontrol
1 more headline
-
first by Wall Street Journal, 6d ago
What people said 24 voices · best of 29 · verbatim
-
K
ROFL! 😹 Hacking OpenAI: A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories # cybersec
-
> By 6:00 a.m. on July 25, we had confirmed local RCE through an image upload. We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target as Opus refused write exploit for remote instances.> When we checked again at 10:00 a.m., the agent had…
-
Takeaways from the WSJ article about @HacktronAI using Claude to get into OpenAI's monorepo and issue a pull request (before stopping and claiming their bug bounty) - how many nation states have already broken in and gone much further and stolen a) algorithmic secrets and b) model weights or c) got...
-
⚠️ Three white hats hacked OpenAI. — They used Anthropic's Claude, and it took them less than 72 hours. — They successfully accessed the OpenAI's internal monorepo (code repository). — OpenAI only awarded them $6,500 for revealing the vulnerability.
-
H
Hacking OpenAI L: https://www. hacktron.ai/blog/hacking-openai C: https:// news.ycombinator.com/item?id=4 9749656 posted on 2026.09.17 at 22:47:24 (c=1, p=7)
-
Reading the patch[0] for libheif the bug which lead to the vuln was around bounds checking for image overlays. the container can have multiple images and you can compose them in the output.heif also supports rotating, cropping, alpha channels, thumbnails and a ton of other features that a web forum where a user is uploading photos or screenshots…
-
OK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggled with the explo...
-
H
Hacking OpenAI Link: https://www. hacktron.ai/blog/hacking-openai Discussion: https:// news.ycombinator.com/item?id=4 9749656
-
> they will do almost anything if they are convinced it is justifiedI’m in the “glorified spell checker” camp, although I don’t mean to reduce their impressive utility and belittle them in the way many people read that term and infer.So I am not sure that an llm “justifies” anything. I mean that their “thinking” text talks about justifications but…
-
They used Opus 5 to pull off the hack. It appears they had access to the loosened cyber-guardrail version of Opus. They successfully accessed the OAI internal monorepo. The question that will be asked is, if these three guys can pull this off, what can a nation state do.
-
Update on the Discourse side, we now run all external binaries, including magick via a landlock sandbox.The gem we use is here: https://github.com/discourse/ruby-landlock highly recommend all Rubyists out there consider this. We are also in the process of moving away from Magick to Vips (which also runs in a sandbox, not in process)HEIF is…
-
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI's internal codebase . It took us <72h. 🧵
-
Unsandboxed ImageMagick is known for being a security nightmare even back when PHP ruled the world (not saying sandboxing is a panacea either, it just requires a different and potentially harder exploit to develop a full chain). Difference is it's easier than ever to turn vulnerabilities into full compromises. At some point we'll have to replace…
-
To demonstrate impact while minimising exposure, we used one affected employee account connected to OpenAI's GitHub org. Codex created a harmless PR in their internal monorepo without us reading sensitive code. That proved to us that the access was real.
-
> Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.> The entire…
-
This is crazy. In late July, “three guys with Claude and Codex subscriptions” were able to use Opus 5 to access OAI auth tokens and gain write access to OpenAI's monorepo openai/openai over the course of two days.
-
We need to be prepared to write less software, with a smaller attack surface. Less is more.Bloated code is the critical problem. Once upon a time, I read C function> char gets(char str);is the first buffer overflow entry point, because it does not check the size of the destination buffer.Sadly we cannot remove it from standard-C yet AFAI Know.The…
-
The second bug is more serious: an OpenAI SSO vulnerability. Using this flaw, we turned our Discourse forum exploit into access to ChatGPT and Codex accounts belonging to people who had signed into it, including OpenAI employees.
-
It is super amazing that 3 years later, none of the models' weights developed by Anthropic or/and OpenAI have leaked so far. Not a single one.Windows internal builds have leaked for years, early game versions, GTA videos, secret documents, whatnot. But somehow even though all the whistleblowing, not a single model was leaked. What level of…
-
really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
-
>...researchers found a bug in the way that the community-discussion forum Discourse processed certain image files. The researchers had access to a special version of Claude Opus 4.8... >At first, it didn’t work. That evening, however, Anthropic released Opus 5 and by the next day, Claude had found a way to exploit the bug...Is this speed of…
-
More details on the OpenAI hack here.
-
> we've built systems that are so goal-oriented, and so capable, that they will do almost anything...I think you mean task oriented, because they're still generally terrible at goal oriented activities except in those domains where the goal can be reduced to a familiar, explicitly practiced task or pattern.
-
Related: Mistral seems to also have been hacked, https://frenchbreaches.com/blog/mistral-ai-de-nouveau-pirate... (NOTE: in French).
All 8 developments of Researchers use Anthropic's Claude to hack into OpenAI's… →
NewswiresBlueskyMastodonXHacker NewsLobstersGoogle NewsReddit