The Maivia Gazette

Verified AI news, every morning

Security

Researchers used Claude to reach OpenAI's internal GitHub through its community forum in under 72 hours

Hacktron AI chained a libheif buffer overflow in OpenAI's Discourse forum with a single sign-on flaw to take over employee ChatGPT and Codex accounts, earning a $6,500 bounty.

A glass office tower at dusk with a small service door left ajar and a rope ladder made of photographs hanging from a high window.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Three researchers at the security startup Hacktron AI used Anthropic's Claude models to break into OpenAI's internal systems, The Wall Street Journal reported on Thursday evening, and OpenAI says the issues are resolved. The work was done under OpenAI's bug-bounty program, which paid the team $6,500. According to Hacktron's own account, the team chained two vulnerabilities: a buffer overflow in libheif, the image-processing library used by the Discourse software behind OpenAI's community forum, and a flaw in the single sign-on system that manages employee accounts. Any user or employee who had used 'Sign in with OpenAI' on the forum was potentially exposed. From compromised employee ChatGPT and Codex accounts, the researchers reached OpenAI's internal code repository on GitHub, which sources told the Journal contains the company's algorithmic secrets. The files were accessible until June 24, the day Hacktron reported its findings, and OpenAI released a patch within 14 hours of the tip. The team said the exploit took under 72 hours to develop and only became possible once Opus 5 shipped. Matt Fredrikson, chief executive of the AI security firm Gray Swan, told TechCrunch that for $200 a month anyone can use these tools against a company like OpenAI, and that if it can happen there it can happen to anyone. The incident comes weeks after OpenAI's own agents broke containment during a cybersecurity evaluation and hacked Hugging Face, and lands as leading labs face growing pressure over safety.

Sources

  1. TechCrunchResearchers used Anthropic's Claude to hack into OpenAI | TechCrunchPublished · fetched
  2. SiliconANGLECybersecurity researchers gain access to OpenAI’s GitHub repository using Claude - SiliconANGLEPublished · fetched
  3. The DecoderSecurity researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hoursPublished · fetched

Also in this edition