Researchers Use Claude to Break Into OpenAI

Cracked open.
Elizabeth Rigsby
Contributing Writer
A glowing digital chain breaks apart at the center, with orange sparks against a dark blue background.
stock.adobe.com - Stock iT

Security researchers used Anthropic’s Claude to help break into OpenAI, gaining access to employee accounts and eventually reaching the company’s internal code during an authorized bug bounty investigation.

A three-person team at Hacktron AI carried out the research, moving from a vulnerability on OpenAI’s public community forum to employee ChatGPT and Codex accounts.

From the first discovery to internal access, the process took less than 72 hours. OpenAI later paid the team a $6,500 bounty.

An earlier Claude model struggled to produce a reliable exploit, while the next version solved the same problem within hours, allowing the researchers to continue testing how far the initial vulnerability could take them.

Why It Matters: Security programs have long relied partly on the time and expertise required to find, develop and connect vulnerabilities. AI can reduce those barriers by making sophisticated exploit research faster and more accessible. That puts more pressure on identity architecture, third-party dependencies and access controls that determine whether a compromise stays contained or becomes a path into more sensitive systems.

  • It Started With an Image Upload: The researchers found a flaw in the software used to process images uploaded to OpenAI’s community forum. By uploading a specially crafted image, they were able to exploit the flaw and gain access to the forum server. The bug had been fixed months earlier, but it never received a CVE designation, which may have contributed to the older, vulnerable version remaining in use.
  • The New Model Made a Difference: Claude Opus 4.8 spent several sessions trying to turn the image-processing flaw into a reliable exploit without success. Anthropic released Opus 5 on July 24, and Hacktron gave the new model the same problem. Within hours, it produced a working exploit that allowed the researchers to continue their testing.
  • Authentication Extended the Access: Once inside the forum server, Hacktron found that session tokens issued through OpenAI’s community sign-in could remain valid for ChatGPT and Codex, including tokens belonging to employees. The issue came from OpenAI’s identity infrastructure, allowing access from the forum to carry over into other services.
  • One Account Reached Internal GitHub: Using an employee account they had accessed, the team found that its Codex account was connected to OpenAI’s GitHub organization. The researchers demonstrated what that access allowed by having Codex create a harmless pull request in OpenAI’s internal code repository without downloading the source code. OpenAI later reported limited reads of private repository metadata and code, revoked affected sessions and narrowed permissions tied to community sign-ins.
  • AI Reduced the Resources Required: Hacktron’s OpenAI research was part of HEIF Heist, a larger project that tested the same image-processing weakness across services including Slack, Zoom and Meta. Three researchers spent about two months on the entire project and less than $3,000 on AI model tokens. According to Hacktron, AI helped compress work that could have required a well-resourced team and months of effort into days.

Go Deeper -> Hackers used Claude to break into OpenAI’s internal code repo – Quartz

Security Researchers Hacked Into OpenAI Using Anthropic’s Claude – Forbes

OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot – The Guardian

Researchers used Anthropic’s Claude to hack into OpenAI – TechCrunch

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters