Hacking OpenAI

ThinkingNews Desk · how this was written
Researchers used Claude to help them hack into OpenAI. The attack involved exploiting vulnerabilities that allowed remote code execution and administrative access to OpenAI’s community forum, enabling compromise of multiple ChatGPT accounts. The researchers reported the findings through Bugcrowd and HackerOne.
Written from all 3 reports below, not from any single one.
How it was reported
- Hacker News·Hacking OpenAI
HacktronAI exposed two critical vulnerabilities that allowed remote code execution and administrative access to OpenAI’s community forum, enabling compromise of multiple ChatGPT accounts. Within 72 hours, the team accessed internal OpenAI repositories, created a proof-of-concept pull request, and reported the findings through Bugcrowd and HackerOne, receiving a $6,500 bounty. The vulnerabilities involved an SSO misconfiguration and a libheif RCE affecting the forum’s image-processing library.
- Ars Technica·Researchers used Claude to hack OpenAI
- The Verge·Security researchers used Claude to help them hack into OpenAI
Related stories
- AI arms race in line for a reckoning after OpenAI hacking incident6 outlets
- In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable4 outlets
- Sources: OpenAI found ~24 incidents of its agents acting in undesirable ways as of mid-September; OpenAI says its agents leaked 53 images from ChatGPT users (Reuters)4 outlets
- OpenAI’s rogue agent breached a second company, executive confirms3 outlets