Researchers use Claude to hack OpenAI
anthropic claude openai
| Source: Mastodon | Original article
Researchers employed Anthropic’s Claude chatbot to ethically hack OpenAI, exposing AI‑driven cybersecurity vulnerabilities.
Researchers at the security startup Hacktron AI have demonstrated that Anthropic’s Claude chatbot can be turned into a hacking tool, using it to breach OpenAI’s internal systems. In a blog post released this week, the team explained how they prompted Claude Opus 4.8 to generate exploit code that leveraged a heap‑buffer‑overflow flaw in the open‑source libheif library. The model‑produced payload was then applied to OpenAI’s staff discussion forum, which runs on the Discourse platform, allowing the researchers to hijack an employee’s ChatGPT account. Through that foothold they accessed OpenAI’s private GitHub repository and other internal resources before responsibly disclosing the vulnerabilities to the company.
The episode underscores a growing security paradox: the same generative AI models that power productivity tools can also automate the creation of sophisticated attacks. By automating code‑generation for exploits, Claude lowered the technical barrier for weaponising software flaws, raising concerns for any organization that integrates AI assistants into its workflow. OpenAI’s reliance on a public‑facing forum for internal communication further illustrates how legacy infrastructure can become an attack surface when paired with powerful language models.
What to watch next includes OpenAI’s remediation plan and any patches to the libheif library or Discourse configuration. Anthropic is likely to review Claude’s safety mitigations to curb malicious code generation. Regulators and industry bodies may also intensify scrutiny of AI‑assisted security testing, potentially prompting new guidelines on responsible model deployment. The incident adds to a string of recent AI‑related breaches, highlighting the urgent need for robust safeguards as generative models become more capable.
Sources
Back to AIPULSEN