top of page
Scheider_300x600.jpeg
nvidio_728x90.png
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Security researchers use Anthropic’s Claude to hack into multiple OpenAI employees’ accounts

Marijan Hassan - Tech Journalist
1 hour ago
2 min read

A three-member team of cybersecurity researchers from startup Hacktron AI - Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini - has demonstrated how AI models can drastically accelerate offensive security workflows.


Editorial credit: PJ McDonnell / Shutterstock
Editorial credit: PJ McDonnell / Shutterstock

Participating in an authorized bug bounty assessment, the researchers leveraged Anthropic’s flagship Claude reasoning models to chain multiple software vulnerabilities together in under 72 hours. Eventually, they obtained administrative access to OpenAI employees' ChatGPT and Codex accounts and reached an internal GitHub repository.


The Exploit Chain: From Forum Image Libraries to Internal Monorepo Access

The attack vector originated not within an AI protocol itself, but inside a third-party software component running on OpenAI’s public community discussion forum.

  • Discourse RCE Vulnerability: The team identified a flaw in the libheif image-decoding library used by the Discourse platform hosting OpenAI's forum. By utilizing Anthropic's Claude models to generate, debug, and port binary exploit scripts, the researchers achieved Remote Code Execution (RCE) on the forum server.

  • SSO Token Reuse: Once inside the Discourse environment, the team extracted active single sign-on (SSO) authentication tokens. Due to a system-wide configuration flaw, these forum authentication tokens remained valid across broader OpenAI services, granting access to ChatGPT and Codex accounts belonging to internal OpenAI employees.

  • Internal Code Repository Reach: Using a compromised Codex session, the researchers navigated to OpenAI's internal "Monorepo", a primary private software repository containing core application logic. To prove access without viewing proprietary model weights or downloading source code, the team executed a harmless pull request modifying an internal documentation file.


Offensive Acceleration and the Compression of Patch Timelines

The exercise highlighted the role of AI as a severe force multiplier for threat research. Hacktron AI reported that early exploit generation attempts using older models failed. However, upon switching to Anthropic’s latest Claude architecture, the model produced a functional exploit binary within hours.


"Work that once required a well-resourced team and months of effort can now be compressed into days," the Hacktron AI team noted, emphasizing that the entire research operation cost less than $3,000 in AI API tokens.


Responsible Disclosure and Remediation

Following the discovery, the researchers privately submitted their findings to OpenAI and Discourse through bug bounty platforms Bugcrowd and HackerOne. OpenAI closed the SSO authentication gap within 14 hours, revoking all affected tokens and narrowing permissions between public forums and internal employee environments. The company also awarded the research team a $6,500 bug bounty for the disclosure.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page