Saturday, 10 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing

TechRadar ·
White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing

Security researchers used Claude Opus 5 to hijack an OpenAI employee's ChatGPT account Exploit abused an image processing flaw on OpenAI community forums to gain full repo access The entire timeline from vulnerability discovery to repo access took less than 72 hours While taking part in an OpenAI bug bounty program, a group of Hacktron security researchers managed to compromise an internal OpenAI ChatGPT account and access internal company code on Github.

According to the Wall Street Journal , who first reported the incident, the researchers used a “special version” of Anthropic’s Claude made available to “qualified cybersecurity practitioners” to pull off the attack.

The researchers initially attempted to use Claude Opus 4.8 to create a breach, but faced multiple setbacks as the model “struggled across several sessions to produce a working exploit.” But the release of Opus 5 changed everything.

OpenAI breach part of wider libheif exploit The breach started with a libheif exploit that abuses a flaw in the .heic/.heif/.avif image file format decoder and encoder.

While this exploit allowed Hacktron to breach OpenAI, libheif is also used across other platforms and software including Slack, Meta, GitHub Enterprise, Ruby on Rails, and more.

To start, the researchers first noted that the OpenAI community forum relies on the Discourse platform, which in turn relies on FastImage for image checks.

But FastImage does not support .heif image files, and these are passed on to ImageMagick for conversion instead.

Developing a working code-execution exploit that abused this relation between ImageMagick and libheif with Opus 4.8 “wasn’t fruitful”, the researchers said, but on the same day Anthropic released Claude Opus 5.

With Opus 5, the researchers managed to create a working local remote code execution (RCE) using the same premise by setting an AI agent in a loop to exploit a local Discourse Cloud instance.

The successful Discourse exploit was then used against the OpenAI community forums, where the researchers hijacked an OpenAI employee’s ChatGPT account.

The employee had connected their ChatGPT Codex with the company’s Github, allowing the researchers full repo access.

Exploit needed just a few hours of human interaction Where the researchers spent hours struggling to create a working exploit with Opus 4.8, the release of Opus 5 showed that “every new model is getting increasingly capable." It took the agent running on Opus 5 just a few hours to develop a working exploit.

The full timeline from initial discovery of the exploit to OpenAI repo access took just 72 hours, researchers noted.

The researchers also said that the entire OpenAI and Discourse hack “took a few days for an agent, and just a few hours of human time” in order to be successful.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›