Ethical Hacking News
Security researchers from a three-person team at Hacktron successfully used Claude to hack into OpenAI's system, highlighting the vulnerability of AI-powered systems and the need for robust security measures. The researchers exploited an issue with the system that processes HEIF images to gain unauthorized access to OpenAI's employee accounts. The incident serves as a wake-up call for the tech industry, emphasizing the importance of robust security measures to protect against AI-powered threats.
Security researchers from Hacktron breached OpenAI's system using the AI model Claude. The breach was facilitated by a vulnerability in the system's image processing and exploitation of the Discourse platform. The Hacktron team used less than $3,000 in tokens to adapt to multiple companies, including OpenAI. The incident highlights the importance of robust security measures to protect against AI-powered threats. OpenAI has acknowledged the vulnerability and is working to strengthen its security. The incident emphasizes the need for continued research and development in AI security.
Security researchers from a three-person team at Hacktron recently utilized Claude, a cutting-edge AI model developed by Anthropic, to breach OpenAI's system. This incident highlights the vulnerability of AI-powered systems and the need for robust security measures to be implemented.
The researchers, who are independent security experts, employed a corrupted image file and forum software to gain unauthorized access to OpenAI's employee accounts. They leveraged an issue with the system that processes HEIF images to exploit the Discourse platform, which hosts OpenAI's community forums. By exploiting this vulnerability, the researchers were able to access OpenAI's instance and access sensitive information.
The Hacktron team's approach to breaching OpenAI's system was facilitated by the newly launched Claude Opus 4.8 and 5. The researchers were able to adapt to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and others, using less than $3,000 in tokens. The vulnerabilities reported by Hacktron have since been fixed, and the team has received $6,500 from OpenAI for their findings.
The incident serves as a wake-up call for the tech industry, emphasizing the importance of robust security measures to protect against AI-powered threats. While OpenAI's system has been compromised, the company has acknowledged the vulnerability and is working to strengthen its security.
In a recent statement, CTO Mohan Pedhapati of Hacktron noted that the team's capabilities are still limited compared to Chinese threat actors. However, the incident highlights the potential risks associated with AI-powered systems and the need for continued research and development in the field of AI security.
The use of Claude, a cutting-edge AI model, to breach OpenAI's system underscores the potential risks and vulnerabilities associated with AI-powered systems. As the tech industry continues to develop and deploy AI-powered systems, it is essential to prioritize robust security measures to protect against potential threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Security-Researchers-Use-Claude-to-Hack-into-OpenAIs-System-ehn.shtml
https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist
Published: Fri Sep 18 12:42:04 2026 by llama3.2 3B Q4_K_M