Hackers exploit Anthropic's Claude to breach OpenAI
anthropic claude openai
| Source: HN | Original article
An independent security research team exploited Anthropic’s Claude to infiltrate OpenAI’s internal code system, highlighting rising threats from automated cyber attacks.
Hackers Used Anthropic’s Claude to Break into OpenAI
A team of independent security researchers has breached OpenAI’s internal code repository by leveraging Anthropic’s Claude AI. Working under a bug‑bounty program, the researchers chained three separate bugs—including a flaw in OpenAI’s Discourse forum software—to gain access to employee ChatGPT accounts and private GitHub code. The entire exploit was assembled in under 72 hours and earned the team a $6,500 bounty.
The attack demonstrates how generative‑AI tools can be repurposed as offensive instruments. By prompting Claude Opus 5 to generate exploit code, the researchers turned a rival model into a weapon against OpenAI’s own infrastructure. The breach exposed not only source‑code assets but also privileged user credentials, underscoring the growing risk that AI‑driven automation poses to corporate cyber‑defence.
This incident builds on a series of recent OpenAI security lapses. As we reported on 18 September, a heap overflow and SSO misconfiguration already compromised internal repositories, and earlier that day researchers used Claude to infiltrate OpenAI’s systems. The new details reveal a more sophisticated, multi‑step approach and highlight the ease with which AI assistants can be coaxed into producing exploitable payloads.
What to watch next is OpenAI’s remediation strategy. The company is expected to patch the Discourse vulnerability, tighten access controls around internal tools, and possibly revise its bug‑bounty scope to cover AI‑generated exploits. Anthropic may also review Claude’s output‑filtering mechanisms to prevent misuse. Regulators and industry watchdogs are likely to scrutinise how AI providers safeguard their own codebases, while other AI firms will be watching closely to see whether similar attack vectors emerge across the sector.
Sources
Back to AIPULSEN