Small cybersecurity startup hacks OpenAI with Claude, earns $6,500 bounty
claude openai startup
| Source: Insider | Original article
A San Francisco cybersecurity startup discovered vulnerabilities in OpenAI’s systems, exploited them using Claude, and earned a $6,500 bounty.
Hacktron, a San Francisco‑based AI cybersecurity startup, disclosed that it breached OpenAI’s infrastructure in July by leveraging Anthropic’s Claude chatbot. The team, led by a researcher named Zhang, found that any user—or OpenAI employee—logging into the company’s community help forum could have had their ChatGPT and Codex accounts compromised. By prompting Claude to generate malicious requests, the researchers were able to hijack employee accounts and access an internal code repository. After reporting the flaws through OpenAI’s bug‑bounty program, the company awarded Hacktron a $6,500 reward.
The incident matters because it demonstrates that AI models themselves can become tools for exploiting rival platforms. Using a competitor’s language model to infiltrate OpenAI’s systems highlights a new attack surface: the “AI‑as‑weapon” vector where generative models automate the discovery and exploitation of vulnerabilities. It also raises questions about the security of shared developer forums and the adequacy of access controls for high‑value AI services such as ChatGPT and Codex, which are increasingly embedded in commercial workflows.
Going forward, observers will watch how OpenAI patches the identified gaps and whether it expands its bounty program to cover AI‑driven attack techniques. Industry peers may reassess their own reliance on third‑party models for internal tooling, and regulators could scrutinise the broader implications of cross‑model attacks on critical AI infrastructure. The episode adds to a growing list of high‑profile security lapses at leading AI firms, underscoring the need for robust, AI‑aware defensive strategies as the technology matures.
Sources
Back to AIPULSEN