Join Nostr
2026-09-18 14:05:53 UTC

oxhak on Nostr: Hacktron AI researchers used Anthropic’s Claude in an OpenAI bug-bounty ...

Hacktron AI researchers used Anthropic’s Claude in an OpenAI bug-bounty investigation to chain two vulnerabilities and access multiple OpenAI employee ChatGPT accounts. One compromised account had Codex connected to OpenAI’s GitHub organization, giving the team access to an internal code repository. OpenAI paid a $6,500 bounty and said the issues were fixed.

The initial entry point was OpenAI’s community forum, where a specially crafted HEIF image triggered a memory bug in the libheif library during Discourse’s image conversion process. The bug had been fixed upstream but had not received a CVE, and the deployed software still used a vulnerable version. Hacktron said Claude Opus 4.8 could not produce a working exploit, while Opus 5 succeeded within hours of release. Discourse issued a fix on July 27. The incident shows how AI tools can reduce the expertise and time needed to develop exploits against complex infrastructure.

https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/