Researchers Use Claude to Breach OpenAI Systems
Security researchers used Anthropic's Claude to breach OpenAI's internal systems, demonstrating how advanced AI models drastically accelerate the speed and ease of complex cyberattacks.

A three-person security team from Hacktron successfully breached OpenAI's internal systems and code repositories in under 72 hours by leveraging Anthropic's AI. The researchers initially attempted the exploit using Claude Opus 4.8, but the model failed to bypass Address Space Layout Randomization (ASLR). However, once Anthropic released Claude Opus 5, the new model generated a functional exploit for a local Mac within three hours and adapted it to the target environment. Running in an autonomous loop, the AI agent took over a test server in four hours, outperforming OpenAI's GPT-5.6 Sol on a related benchmark.
The attack targeted OpenAI's community forum at community.openai.com, exploiting two chained vulnerabilities. First, the team targeted an unpatched flaw in libheif, an image processing library used by the forum software, Discourse, to handle HEIC files. Second, they exploited a misconfiguration in OpenAI's single sign-on system. By compromising the forum, the researchers could impersonate active members and hijack employee ChatGPT and Codex accounts. To demonstrate their access, they used a compromised Codex account to submit a harmless pull request to OpenAI's internal GitHub monorepo, though they did not view sensitive data.
This intrusion was part of a broader two-month research initiative called "HEIF Heist," which targeted other major platforms including Slack, Meta, and GitHub Enterprise. The entire project cost less than $3,000 in AI expenses, with subsequent adaptations to new targets requiring only one to two days. Out of all the organizations tested, only Shopify detected the malicious activity. OpenAI patched the vulnerability approximately 14 hours after receiving the report, and Discourse resolved the issue shortly after. The researchers noted that AI-driven automation effectively eliminates the traditional protection of software complexity by replacing scarce human expertise with cheap computing power.
This is our own summary of reporting by The Decoder



