Ethical Hacking News
Three Hackers Used Claude to Break Into OpenAI In Less Than 72 Hours, Exposing the Vulnerabilities of Modern AI Systems
Three independent cybersecurity researchers, operating under the alias Hacktron, broke into ChatGPT and Codex accounts of multiple OpenAI employees, gaining access to sensitive company information. The breach, carried out as part of OpenAI's bug bounty program, highlights the vulnerabilities of modern AI systems and the need for robust cyber defenses. The Hacktron researchers used vulnerabilities that could easily have been discovered by someone with malicious intentions, demonstrating the potential risks of AI system security. The incident underscores the importance of addressing the vulnerabilities inherent in modern AI systems and the need for a bug bounty program to strengthen cyber defenses. The breach has significant implications for the company and the tech industry, emphasizing the need for prioritizing the security of AI systems and adopting robust cyber defenses.
In the realm of artificial intelligence (AI), a recent breach of OpenAI's systems has shed light on the vulnerabilities of modern AI systems. The incident, which occurred in July 2026, involved three independent cybersecurity researchers, operating under the alias Hacktron, who managed to break into the ChatGPT and Codex accounts of multiple OpenAI employees, giving them access to a potential cache of highly sensitive company information. This breach, although carried out with the intention of discovering vulnerabilities as part of OpenAI's bug bounty program, has significant implications for the company and the tech industry as a whole.
According to the context data, the Hacktron researchers, consisting of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, used vulnerabilities that could easily have been discovered and exploited by someone with much less friendly intentions. Their initial discovery of a security flaw in the image-upload software used by Discourse, an online discussion platform utilized by OpenAI, marked the beginning of their journey. Utilizing Anthropic's Claude Opus 4.8, they began by attempting to generate code that would allow them to upload malicious files, acting as a digital Trojan horse, through which they could gain private access to discussions hosted on the site.
Initially, their efforts were unsuccessful, but the release of Anthropic's Opus 5 model the following day proved to be a turning point. Early in the morning of July 25, the Hacktron team discovered that Opus 5 had successfully exploited the Discourse bug, allowing them to view an internal OpenAI discussion forum containing employees' authentication tokens, unique digital codes enabling access to apps or websites. This access could have been utilized to access employees' ChatGPT and Codex accounts, potentially leading to the exposure of highly sensitive company information.
Within an OpenAI employee's Codex account, the Hacktron team submitted a pull request, serving as a form of digital evidence to prove their presence without retrieving any sensitive company data. Their actions, which took place over a mere 72 hours, underscored the vulnerability of companies' cyber defenses in the face of modern AI systems.
The breach, although carried out with the intention of discovering vulnerabilities, has significant implications for the company and the tech industry. The rapid evolution of AI agents is far outpacing the science of "alignment," which is focused on ensuring that these systems do not behave in unpredictably destructive ways. The recent hack of OpenAI, carried out by the Hacktron researchers, serves as a stark reminder of the need for robust cyber defenses and the importance of addressing the vulnerabilities inherent in modern AI systems.
Furthermore, the breach highlights the importance of a bug bounty program, which can help companies identify vulnerabilities and strengthen their cyber defenses. The Hacktron researchers, who were paid $6,500 for their efforts, demonstrate the value of such programs in ensuring the security of AI systems.
The recent hack of OpenAI is part of a broader effort throughout the tech industry to shore up its cyber defenses at a time when the evolution of AI agents is far outpacing the science of alignment. The incident serves as a wake-up call, emphasizing the need for companies to prioritize the security of their AI systems and to adopt robust cyber defenses to prevent similar breaches in the future.
In light of the recent hack of OpenAI, it is essential to consider the implications of this incident and the potential consequences of a breach carried out by a malicious actor. The rapid evolution of AI agents and the significant vulnerabilities inherent in modern AI systems underscore the need for robust cyber defenses and the importance of addressing the vulnerabilities inherent in these systems.
In conclusion, the recent hack of OpenAI serves as a stark reminder of the need for robust cyber defenses and the importance of addressing the vulnerabilities inherent in modern AI systems. The incident, although carried out with the intention of discovering vulnerabilities, highlights the significance of a bug bounty program and the importance of prioritizing the security of AI systems.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-the-Vulnerabilities-of-Modern-AI-Systems-A-Deep-Dive-into-the-Recent-Hack-of-OpenAI-ehn.shtml
https://gizmodo.com/three-hackers-used-claude-to-break-into-openai-in-less-than-72-hours-2000814009
Published: Fri Sep 18 12:56:30 2026 by llama3.2 3B Q4_K_M