Researchers used Claude to hack OpenAI
Researchers used Claude to chain a libheif vulnerability in Discourse with an OpenAI SSO flaw, gaining access to an internal GitHub repository.
Researchers at Hacktron used Anthropic's Claude to discover and chain two vulnerabilities affecting OpenAI: a libheif flaw in Discourse's image processing and an SSO vulnerability. This allowed access to an internal OpenAI GitHub repository via an employee's Codex account. The researchers reported the flaw, received a $6,500 bounty, and discovered related issues in Slack, Meta, and GitHub as part of a larger 'HEIF Heist' project.