Top Stories
3 outlets·3 reports·over 13h

Hacking OpenAI

ThinkingNews Desk · how this was written

Researchers used Claude to help them hack into OpenAI. The attack involved exploiting vulnerabilities that allowed remote code execution and administrative access to OpenAI’s community forum, enabling compromise of multiple ChatGPT accounts. The researchers reported the findings through Bugcrowd and HackerOne.

Written from all 3 reports below, not from any single one.

How it was reported

  1. Hacker News·
    Hacking OpenAI

    HacktronAI exposed two critical vulnerabilities that allowed remote code execution and administrative access to OpenAI’s community forum, enabling compromise of multiple ChatGPT accounts. Within 72 hours, the team accessed internal OpenAI repositories, created a proof-of-concept pull request, and reported the findings through Bugcrowd and HackerOne, receiving a $6,500 bounty. The vulnerabilities involved an SSO misconfiguration and a libheif RCE affecting the forum’s image-processing library.

  2. Ars Technica·
    Researchers used Claude to hack OpenAI
  3. The Verge·
    Security researchers used Claude to help them hack into OpenAI

Related stories

Share: