Research

Researchers Breach OpenAI Using Anthropic's Claude

A three-person security team used Anthropic's Claude models to breach OpenAI employee accounts, demonstrating how easily commercial AI can be weaponized to exploit critical software bugs.

The Verge AI4 days agoResearch
Image: The Verge AI

Security researchers from the firm Hacktron successfully compromised OpenAI employee accounts in under 72 hours by leveraging Anthropic's Claude Opus 4.8 and 5 models. The three-person team targeted Discourse, the third-party forum software hosting OpenAI's community boards, by exploiting a vulnerability in how the system processes HEIF image files. After Claude Opus 5 launched on the evening of July 24th, the researchers achieved remote code execution on Discourse Cloud by 10:00 AM the following morning, granting them access to OpenAI's instance.

Once inside, the team accessed OpenAI's GitHub repository, known as "Monorepo," which houses the company's core algorithmic secrets. While the researchers refrained from downloading internal code, they demonstrated their access by sending a pull request from an employee's Codex account. The broader "HEIF Heist" initiative required less than $3,000 in AI tokens and was adapted within two days to target other major platforms, including Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick. Of all the targeted organizations, only Shopify detected the intrusion.

Discourse and OpenAI have since patched the security flaws, and OpenAI awarded Hacktron a $6,500 bug bounty. However, the incident serves as a stark warning for cybersecurity practitioners. Hacktron CTO Mohan Pedhapati noted that the team was merely "three guys with Claude and Codex subscriptions," suggesting that well-funded state actors possess far greater capabilities. For security professionals, this breach underscores the urgent need to secure third-party integrations and prepare for a new era of highly automated, AI-driven penetration testing that dramatically lowers the barrier to entry for sophisticated cyberattacks.

This is our own summary of reporting by The Verge AI

More in Research