Security Researchers Breach OpenAI Employee Accounts with Artificial Intelligence Assistance
Independent researchers used Anthropic's AI models to gain access to OpenAI employee accounts in less than three days, reaching a GitHub repository containing algorithmic secrets.
Three independent security researchers within Hacktron used Anthropic Claude models to successfully breach OpenAI employee accounts in less than 72 hours, accessing a GitHub repository containing algorithmic secrets.
Development and Process of the Incident
According to information reported by the Wall Street Journal, the Hacktron team of three independent security researchers completed the operation to infiltrate OpenAI systems using Anthropic's Claude Opus 4.8 and 5 models in under 72 hours.
Access to the GitHub Repository
The researchers managed to gain access to a GitHub repository called Monorepo, which reportedly houses OpenAI's algorithmic secrets. While avoiding direct intervention in the internal code, the team submitted a pull request through an employee's Codex account to prove access.
Discourse Vulnerability and Exploitation
The infiltration was carried out by exploiting a vulnerability in the HEIF image processing system of Discourse, a third-party service hosting OpenAI's community forums. Shortly after the release of the Claude Opus 5 model, the researchers obtained remote code execution capabilities on Discourse Cloud.
Cost, Scope, and Reward
Under the HEIF Heist project, various platforms including OpenAI could be targeted with a token cost of less than $3,000. The reported vulnerabilities were fixed by Discourse and OpenAI, and OpenAI paid $6,500 to the team that discovered the security flaw.