Skip to content

Security researchers used Claude to help them hack into OpenAI

7.9 relevance
Score Breakdown
technical depth
8
novelty
9
actionability
6
community
8
strategic
8
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Security researchers used Claude to hack OpenAI; highly relevant and actionable.

AI/ML theverge.com
Robot hacker typing on a keyboard.
Summary

A three-person Hacktron team used Anthropic's Claude Opus 4.8 and 5 to hack into OpenAI in under 72 hours, exploiting a HEIF image processing flaw in Discourse Cloud to achieve RCE and access the Monorepo containing algorithmic secrets. They sent a pull request from an employee's Codex account to prove access, spent less than $3,000 in tokens on the campaign, and were only detected by Shopify among multiple targets. OpenAI later paid them a $6,500 bug bounty.

Author

Stevie Bonifield

More from Stevie Bonifield →