Researchers Use AI To Breach Openai Security
Security researchers exploited vulnerabilities using Anthropic's Claude to infiltrate OpenAI, highlighting potential risks in AI-driven security.
In a striking demonstration of AI's evolving capabilities, a team of independent security researchers successfully breached OpenAI's defenses using Anthropic's Claude AI model. The incident, reported by both The Verge and TechCrunch, underscores the vulnerabilities even advanced tech companies face in the age of AI-driven security.
Table of Contents
What Happened
A team of three researchers from Hacktron AI utilized Anthropic’s Claude Opus 4.8 and 5 to hack into OpenAI. According to The Verge, the breach was accomplished in under 72 hours by exploiting vulnerabilities in Discourse, the software hosting OpenAI’s community forums. The researchers accessed OpenAI employee accounts and managed to send a pull request from an employee’s Codex account to demonstrate their access to OpenAI’s GitHub repository, known as "Monorepo."
Details and Context
The attack was part of an OpenAI bug-bounty program, as reported by TechCrunch. The researchers discovered a flaw in how Discourse processed HEIF image files, leveraging a memory bug in the libheif library. This allowed them to execute remote code on the Discourse server, subsequently gaining access to OpenAI employee accounts. The Verge notes that Hacktron's project, dubbed "HEIF Heist," was adaptable to various companies and cost less than $3,000 in tokens.
The Claude Opus 5 model, released on July 24, played a crucial role in the breach. As per TechCrunch, the previous version, Opus 4.8, struggled to create a working exploit, but Opus 5 succeeded within hours of its release. The researchers reported the vulnerabilities to OpenAI and Discourse, both of which have since patched the issues. OpenAI rewarded Hacktron with $6,500 for their findings.
Implications for Tech Professionals
This incident highlights the growing capabilities of AI in cybersecurity, raising questions about the future of digital security. As noted by TechCrunch, the ease with which Hacktron executed the breach using off-the-shelf AI tools suggests that even well-secured organizations are vulnerable. Matt Fredrikson, CEO of Gray Swan, emphasized the potential risks, stating that if a small team could breach OpenAI, larger entities or nation-states might pose even greater threats.
For tech professionals and companies in the USA and Israel, this event underscores the need for heightened vigilance and the continuous updating of security protocols. It also suggests that AI tools, while powerful, can be double-edged swords, capable of both defending and attacking digital infrastructures.
Sources
This story was compiled by AI from the reports below. Read the originals for the full details.