Hacktron researchers breach OpenAI, exposing employee account vulnerabilities
White-hat hackers chained two flaws to access employee ChatGPT accounts; OpenAI has patched the holes.
What to know
- Hacktron researchers breached OpenAI in July by chaining two unknown vulnerabilities in Discourse and OpenAI's employee validation system to access employee ChatGPT accounts, demonstrating a white-hat proof-of-concept that caused no damage.
- OpenAI has patched both vulnerabilities and paid Hacktron $6,500 through its bug bounty program for responsible disclosure.
- Security experts warn the vulnerability chain mirrors tactics used by nation-state-backed hackers, raising concerns about industrial espionage and AI model theft in a highly competitive field.
- The breach disclosure intensifies a wave of AI safety and security concerns, as safety researchers have recently resigned from major companies and called for stronger safeguards.
“The hack conducted demonstrates the need for constant vigilance in these environments and when there's so many moving parts and the pressure to constantly develop and be delivering; patches get neglected, configurations get missed and cracks in layers of security get exposed”
Greg Linares, Cybersecurity researcher, Persona · NBC News ↗
Hacktron Cybersecurity research firmOpenAI AI companyGreg Linares Cybersecurity researcher, Persona
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
1
Security expert warns vulnerability type matches nation-state tactics
Greg Linares, a cybersecurity researcher at Persona, tells NBC News that the vulnerability chain Hacktron exploited mirrors techniques used by advanced persistent threats and nation-state-backed hackers. He emphasizes the need for constant vigilance as AI companies balance rapid development with security.
“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets…”
— Greg Linares -
first by NBC News, 5d ago
-
-
2
NBC News reports on Hacktron breach and OpenAI response
NBC News covers the Hacktron announcement. OpenAI spokesperson confirms the breach, states vulnerabilities have been patched, and thanks the researchers for responsible disclosure. OpenAI paid $6,500 through its bug bounty program.
“We thank the researchers for contacting us and sharing their findings…”
— OpenAI spokesperson -
background
Hacktron announces the breach publicly — The researchers disclosed their findings in a blog post, revealing how they chained together the two vulnerabilities. This marked the first public disclosure of the security gaps.
-
background
Hacktron conducts 72-hour breach of OpenAI systems — Researchers at cybersecurity firm Hacktron exploited two unknown vulnerabilities—one in Discourse and one in OpenAI's employee validation system—to access employee ChatGPT accounts. The operation occurred in late July and caused no harm to OpenAI's systems.