ZeroHour
The Verge · AIpublished ()ingested Stevie Bonifield
Part of a story covered by 2 sources: “Researchers used Anthropic's Claude to hack into OpenAI employee accounts via Discourse HEIF flaw” — merged summary and timeline →

Security researchers used Claude to help them hack into OpenAI

mediumAI safety & security exploited in the wildimportance 66
AI summary · glm-5.3-flash

Three Hacktron researchers used Claude Opus to breach OpenAI employee accounts through a Discourse HEIF flaw, reaching the Monorepo within 72 hours.

A three-person team at Hacktron used Anthropic's Claude Opus 4.8 and 5 to exploit a HEIF image-processing flaw in Discourse, achieving RCE on Discourse Cloud and access to OpenAI's community forum instance within roughly a day of Claude Opus 5's July 24 launch. They reached OpenAI's GitHub Monorepo through employee accounts and proved access with a pull request from an employee's Codex account. Their HEIF Heist tooling adapted to targets including OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens, and was detected by only one target, Shopify. Discourse and OpenAI have since fixed the reported vulnerabilities, and OpenAI paid a $6,500 bounty.

  • Three researchers achieved Discourse Cloud RCE within a day using Claude Opus 5
  • Accessed OpenAI GitHub Monorepo and sent PR from an employee's Codex account
  • Tooling adapted to OpenAI, Slack, Meta, GitHub Ent for under $3,000 in tokens
  • Only Shopify detected the activity; OpenAI paid a $6,500 bounty
  • Discourse and OpenAI have since fixed the vulnerabilities
Full article294 words · extracted from theverge.com · click to collapse

Stevie Bonifield

is a news writer covering all things consumer tech. Stevie started out at Laptop Mag writing news and reviews on hardware, gaming, and AI.

A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, the Wall Street Journal reports. They were able to access OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to the Wall Street Journal’s sources.

They stopped short of accessing internal code in Monorepo themselves, but sent a pull request from an employee’s Codex account to prove they gained access. They were able to get in through Discourse, the third-party service that hosts OpenAI’s community forums, by exploiting an issue with the system it uses to process HEIF images. According to Hacktron, Claude Opus 5 launched in the evening on July 24th, and by 10AM the next day they had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.

Their HEIF Heist project took “only one or two days” to adapt to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using less than $3,000 in tokens, and to their knowledge, was only detected by one target, Shopify. The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron says OpenAI paid it $6,500 for finding the bug, but as Hacktron CTO Mohan Pedhapati said to the WSJ, “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

  • Stevie Bonifield

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist