Security researchers used Claude to help them hack into OpenAI
Key Points:
- A team of three independent security researchers at Hacktron hacked into OpenAI employee accounts within 72 hours using Anthropic’s Claude Opus 4.8 and 5, gaining access to OpenAI’s GitHub repository "Monorepo," which contains sensitive algorithmic information.
- They exploited a vulnerability in Discourse, the third-party platform hosting OpenAI’s community forums, by manipulating the system’s processing of HEIF images to achieve remote code execution (RCE) on Discourse Cloud.
- The researchers demonstrated access by sending a pull request from an employee’s Codex account but did not directly access internal code in the Monorepo themselves.
- Hacktron adapted their "HEIF Heist" exploit to target multiple companies, including Slack, Meta, GitHub, and others, with minimal cost and detection, highlighting widespread vulnerability in image processing systems.
- The reported vulnerabilities have been fixed, OpenAI paid Hacktron $6,500 for the bug, and Hacktron emphasized their modest capabilities compared to state-sponsored threat actors despite the significant impact of their findings.