Security researchers used Claude to help them hack into OpenAI
7.9 relevance
Score Breakdown
technical depth 8
novelty 9
actionability 6
community 8
strategic 8
personal 9
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Security researchers used Claude to hack OpenAI; highly relevant and actionable.
Summary
A three-person Hacktron team used Anthropic's Claude Opus 4.8 and 5 to hack into OpenAI in under 72 hours, exploiting a HEIF image processing flaw in Discourse Cloud to achieve RCE and access the Monorepo containing algorithmic secrets. They sent a pull request from an employee's Codex account to prove access, spent less than $3,000 in tokens on the campaign, and were only detected by Shopify among multiple targets. OpenAI later paid them a $6,500 bug bounty.