· · 7 sources ·Updated

Hacktron researchers used Anthropic Claude to breach OpenAI systems

A three-person team from Hacktron AI exploited vulnerabilities in an OpenAI forum using Anthropic's Claude chatbot starting on July 23.

OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot
File photo OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot Photo: The Guardian

Vulnerability exploitation details

The researchers combined a flaw in the Discourse forum software with a problem in the sign-on system. They used specially prepared image data to trigger remote code execution on the platform. OpenAI confirmed that the team accessed employee accounts and demonstrated entry into their private code repository.

Bug bounty outcome

The group reported the issues through OpenAI's bug-bounty programme before stopping testing without examining source code. The Wall Street Journal reported that OpenAI paid the team $6,500 for their discovery. An OpenAI spokesperson stated the company had addressed the vulnerabilities and fixed them within about 14 hours.

7 outlets, different leads

  • Express Tribune

    Anthropic's Claude helped cybersecurity researchers breach OpenAI: report

  • Anadolu Agency

    Anthropic's Claude helped cybersecurity researchers breach OpenAI: Report

  • The Guardian

    OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot

  • Ars Technica

    Researchers used Claude to hack OpenAI

  • TechCrunch

    Researchers used Anthropic’s Claude to hack into OpenAI

  • Dawn

    Researchers used Claude to breach OpenAI's internal systems

  • The Verge

    Security researchers used Claude to help them hack into OpenAI

Reported by

7 independent outlets. Headlines as published. Links open the original report.