Claude fails to hack OpenAI, then Anthropic ships Opus 5
anthropic claude openai
| Source: HN | Original article
Researchers leveraged Anthropic's new Claude Opus 5 to chain two vulnerabilities, creating a path from a forum image upload to OpenAI's internal GitHub.
Security researchers have demonstrated that Anthropic’s latest Claude model, Opus 5, can be weaponised to breach OpenAI’s internal systems. Over a 72‑hour window the team chained two separate flaws—an image‑decoder vulnerability and a weakness in OpenAI’s community‑forum upload flow—to gain footholds on employee ChatGPT and Codex accounts, then pivoted to an internal GitHub repository containing source code. The same researchers previously attempted a similar attack with an earlier Claude version but were stopped by a common security control; Opus 5 succeeded where its predecessor could not.
The experiment, conducted by three independent security analysts, was framed as an “ethical hack” and reported to OpenAI before any data was exfiltrated. By automating exploit development and code manipulation, the new Claude model dramatically compressed the time and expertise traditionally required for such intrusions. The episode underscores a growing tension: advanced generative‑AI coding assistants are becoming powerful tools for both developers and attackers, reshaping the economics of vulnerability exploitation.
As we reported on 19 September, a small cybersecurity startup previously used an earlier Claude model to breach OpenAI and earned a bounty for the disclosure. The latest Opus 5 breach suggests that model upgrades can quickly outpace existing defensive measures, raising questions about responsible deployment and oversight of AI assistants in security‑critical contexts.
Going forward, observers will watch for Anthropic’s response—whether it will introduce usage safeguards, model‑level throttling or tighter integration with security‑testing frameworks. OpenAI is expected to detail any remediation steps and may reassess its reliance on external AI tools for internal development. The broader AI community will likely debate how to balance rapid model innovation with the need for robust, pre‑deployment security vetting.
Sources
Back to AIPULSEN