Skip to content

Researchers used Anthropic’s Claude to hack into OpenAI

7.7 relevance
Score Breakdown
technical depth
8
novelty
9
actionability
5
community
8
strategic
8
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Novel use of AI agents for cybersecurity, highly relevant to AI/ML and security.

AI/ML techcrunch.com
Researchers used Anthropic’s Claude to hack into OpenAI
Summary

Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to chain two vulnerabilities—a libheif memory bug in Discourse forum software and a subsequent account takeover—to access OpenAI employee ChatGPT and Codex accounts, earning a $6,500 bug bounty. The exploit succeeded only after Opus 5 was released, as Opus 4.8 failed to produce a working exploit, highlighting how rapidly improving AI models can lower the barrier for sophisticated attacks. The libheif bug had been patched months earlier but lacked a CVE identifier, leaving Discourse running the vulnerable version.

Author

Aditya Mehta, Rebecca Bellan

More from Aditya Mehta, Rebecca Bellan →