Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Growth stocks coverage continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK

Tech

Anthropic View profile

Researchers used Anthropic's Claude to break into OpenAI's systems

White-hat team chained a forum image flaw with a sign-on weakness to reach an employee's account and internal code

The image depicts a hooded figure focusing intently on a laptop screen in a dimly lit environment. The glow from the screen and background lights creates a dramatic contrast, sugge — Credit: AI-generated (Midjourney)
AI-generated (Midjourney)

Security researchers used artificial intelligence models built by Anthropic, the developer of the Claude chatbot, to break into the internal systems of OpenAI, the maker of ChatGPT, the Wall Street Journal reported.

The three researchers, from the security firm Hacktron AI, compromised an employee ChatGPT account and demonstrated a route to OpenAI's private code on GitHub.

The work was authorised and carried out through OpenAI's bug bounty programme, which pays outsiders who report security flaws.

OpenAI paid the team $6,500 for the discovery, thanked the researchers and said it had fixed the issues.

The attack began at OpenAI's community forum, which runs on Discourse, an open-source discussion platform.

Hacktron found that certain uploaded images were passed to libheif, an open-source image-decoding library, in a version that carried a heap buffer overflow, a memory flaw that can let an attacker run their own code on a server.

A separate misconfiguration in OpenAI's single sign-on system then let the researchers obtain identity tokens and take over the ChatGPT accounts of forum members, including OpenAI staff.

Those accounts opened a path to internal code through GitHub, showing how a breach of a public forum could extend into connected company systems.

To show the reach of the access without exposing sensitive code, the team used a compromised account to open a single harmless change request in OpenAI's repository.

Hacktron said it first tried Claude Opus 4.8 but found the model struggled to produce a reliable exploit, and turned to the newer Opus 5 to finish the work.

The claim matters because building this type of exploit has traditionally required specialist expertise and heavy manual effort.

The researchers said the wider campaign, which traced the same library flaw across other large platforms, cost less than $3,000 in AI usage and took two months.

Testing the forum software itself fell outside the scope of OpenAI's bounty programme.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK