This tiny cybersecurity startup managed to hack OpenAI using Claude, and won a $6,500 bounty
An AI startup found vulnerabilities in OpenAI's infrastructure. illustration by Leon Neal/Getty Images Hacktron, a small cybersecurity startup, hacked into OpenAI's codebase with the help of Claude.
The company flagged vulnerabilities in OpenAI's systems and was paid $6,500 for the discovery.
The potential for malicious AI agents to go unchecked has recently spurred fears of an AI apocalypse.
A small AI startup used Claude to hack into OpenAI's internal codebase shortly after the OpenAI Hugging Face hack .
Zayne Zhang, the cofounder and CEO of Hacktron, told Business Insider that his research team has begun investigating security vulnerabilities at frontier AI companies like OpenAI to determine whether they have gaps that could be exploited by AI agents.
Hacktron is a San Francisco-based AI cybersecurity startup.
In July, Zhang's team discovered some gaps in OpenAI's infrastructure.
According to Hacktron's disclosure about the incident, published on Sunday, any user or OpenAI employee logging into OpenAI's community help forum could have had their ChatGPT and Codex accounts hacked.
Hacktron then tried to exploit that vulnerability via Claude.
The company had access to Anthropic's Cyber Verification Program, which relaxed certain cyber restrictions on Claude for authorized security research, Zhang said.
The team managed to hack into an OpenAI employee's account and prompt the employee's Codex account to suggest changes in OpenAI's internal code repository.
Hacktron said the team stopped there, didn't access any internal code, and flagged the issue to OpenAI.
Hacktron said in its disclosure that the company won a $6,500 bounty from its discovery.
The startup was launched less than a year ago and has fewer than 10 employees.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.businessinsider.com — the content belongs to Business Insider.