Claude Helped Crack OpenAI—and Rekindled the Open-Model Fight

A three-person Hacktron AI team used Anthropic’s Claude to chain flaws in OpenAI’s systems and earn a $6,500 bounty. The breach has sharpened a familiar divide: whether danger is concentrated inside elite labs or spread by increasingly capable AI tools.
Claude Helped Crack OpenAI—and Rekindled the Open-Model Fight

Claude Helped Crack OpenAI—and Rekindled the Open-Model Fight
On July 25, Hacktron AI researchers found an entry point into OpenAI’s systems through its community forum, which ran on Discourse. A crafted HEIF or HEIC image could exploit an unpatched memory flaw in the libheif image-decoding library, giving the team control of the forum server.

The first version of Anthropic’s model available to the researchers, a special Claude Opus 4.8 build, did not immediately produce a working exploit. That changed after Opus 5 was released. “Opus 4.8 struggled across several sessions to produce a working exploit,” Hacktron wrote; when given the same task after the newer model arrived, “it succeeded.”

From the compromised server, the team chained a second flaw that enabled it to take over ChatGPT and Codex accounts, including accounts belonging to OpenAI employees. One employee’s Codex connection led to OpenAI’s GitHub organization, the researchers said. Hacktron notified OpenAI and Discourse; Discourse issued a fix on July 27, and OpenAI later resolved the issues and paid the team a $6,500 bug bounty.

The episode has since become a warning about the speed with which AI can turn scarce technical expertise into a more widely available capability. Researchers who breached OpenAI said the industry was unprepared for security risks created by the growing power of its own technology. As AI-security executive Matt Fredrikson put it, “For $200 a month, anyone can use these tools and hack into a company like OpenAI.”

But the political reading is contested. Hugging Face chief executive Clement Delangue argued that, as in biology and cybersecurity, risk is “concentrated and created by the few most powerful labs,” and that open-source AI can be a mitigation rather than the central threat. The breach does not settle that dispute. It does make the stakes harder to ignore: frontier capability is no longer just a product race; it is a security variable.

https://foxvector.com

Write a comment