Researchers use Claude to breach ChatGPT in under 72 hours
Security researchers demonstrated AI-powered hacking by using Anthropic's Claude to penetrate OpenAI systems, highlighting urgent vulnerabilities in leading language models.
What to know
- Researchers breached ChatGPT in under 72 hours using Claude, accessing an employee account, source code repository details, and forums—then responsibly reported the vulnerability.
- OpenAI patched the flaw and paid a $6,500 bounty; the breach was part of a legitimate bug-hunting program.
- Security experts argue the real near-term risk is insufficient technical guardrails, not superintelligent AI—and warn AI-powered attacks threaten critical infrastructure.
- The breach joins recent incidents like the July Hugging Face hack, prompting calls from AI leaders including Anthropic's CEO for the industry to slow development pace.
“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch. We appreciate their attention to detail and fast resolution of this issue.”
Hacktron AI, Security research platform · CBS News ↗
Hacktron AI Security research platformOpenAI ChatGPT developerAnthropic Claude AI developer
Dario Amodei Anthropic CEO
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
2
OpenAI patches vulnerability and pays bounty
OpenAI responded promptly to the reported breach, narrowed permissions on Community sign-in tokens, revoked affected tokens and sessions, and paid the researchers a $6,500 bounty.
“We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
— OpenAI -
AI cybersecurity risks explode as Anthropic's Claude used to break into OpenAI's ChatGPT systems
-
-
background
Hacktron AI researchers breach ChatGPT using Claude — Security researchers from Hacktron AI used Anthropic's Claude to gain access to an OpenAI employee's ChatGPT account, retrieve source code repository details, and access an OpenAI discussion forum. The entire process took less than 72 hours.
-
1
Experts attribute breaches to guardrail gaps, not superintelligence
Analysis indicates recent breaches result from insufficient technical guardrails leaving networks vulnerable, rather than from developing superintelligence as some AI leaders warn. Business executives and ex-government officials voice concern that AI-powered cyberattacks could threaten critical infrastructure, while the Pentagon's outdated computer networks have exacerbated cybersecurity risks.
“The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours.”
— Hacktron AI, Security research platform · source -
first by Semafor, 5d ago
-