12 hrs ago

Researchers Used Claude to Reach OpenAI Internal Systems

Researchers Used Claude to Reach OpenAI Internal Systems
OpenAI hack: 3 Indian-origin researchers used Anthropic’s Claude to breach systems · indianexpress.com

Three security researchers were testing OpenAI’s systems with permission.

They found a weakness in software used for OpenAI’s online forum.

Anthropic’s Claude helped them write a program that used the weakness.

This let them obtain login tokens connected to some OpenAI employees’ accounts.

One account could reach OpenAI’s private software area.

The researchers made a small proposed documentation change to prove they had access.

They said they did not download private source code or model weights.

OpenAI and Discourse fixed the problems, and OpenAI paid the team a $6,500 reward.

The incident shows that AI can help security researchers find flaws faster, but people still directed the testing.

Key facts

Researchers
Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini of Hacktron AI
Bounty
$6,500, reported as approximately ₹6.27 lakh
Initial flaw
A vulnerability involving the processing of certain HEIC/HEIF image files in Discourse’s image-processing chain
AI assistance
Claude Opus 4.8 initially failed to produce a reliable exploit; the researchers said Claude Opus 5 succeeded within hours
Potential access
Authentication tokens, several OpenAI employees’ ChatGPT and Codex accounts, and OpenAI’s private GitHub environment
Repository
OpenAI’s Monorepo, which was reported to contain important software and algorithmic material but not model weights
Remediation
OpenAI revoked affected tokens and sessions and narrowed Community sign-in permissions; Discourse fixed its vulnerability

Quotes

Mohan Pedhapati

Hacktron AI chief technology officer and member of the research team

“I don’t think we are as strong as Chinese threat actors. We’re just three guys with Claude and Codex subscriptions.”
indianexpress.com
“Work that once required a well-resourced team and months of effort can now be compressed into days.”
indianexpress.com

OpenAI spokesperson

Representative of OpenAI responding to the reported vulnerabilities

“We thank the researchers for contacting us and sharing their findings.”
indianexpress.com

Sources

Related news