Hacktron AI Team Discovers Vulnerability in OpenAI Forum Using Claude Model
Cybersecurity researchers from Hacktron AI used Anthropic's Claude model to discover a vulnerability in OpenAI's forum and gained access to the company's systems.
The cybersecurity team of Hacktron AI discovered and exploited a software vulnerability in OpenAI's discussion forum using Anthropic's Claude model. While the researchers gained access to employee accounts and the software repository through the authentication systems they acquired, OpenAI stated that the issue has been resolved and the team was awarded a bug bounty.
Discovery of the Vulnerability and the Role of the Claude Model
The Hacktron AI cybersecurity team identified a software bug in the discussion forum used by OpenAI, stemming from the way image files were processed. The researchers asked a custom Claude model to write an exploit code to leverage this vulnerability.
Generated with the support of Claude's new version, the exploit code enabled the researchers to successfully access the server hosting OpenAI's forum.
Access to Employee Accounts and Internal Data
Having infiltrated the server, the researchers reached authentication systems that allow users to access online services.
It was determined that these authentication systems were valid on ChatGPT and some belonged to OpenAI employees.
Controlled Proof of Concept via GitHub
Realizing they could access sensitive data, the team examined these systems, which could also be used to gain access to OpenAI's software repository service, GitHub.
Using just one employee's account, a harmless pull request was submitted to the company's internal code repository without touching any sensitive code.
OpenAI's Response and Reward Process
The researchers reported their findings and access evidence to OpenAI and Discourse, the company that developed the forum software, prompting prompt action.
Upon notification, OpenAI announced that the security vulnerability had been fixed and awarded the research team a bug bounty of $6,500.