OpenAI · Claude · Taiwan · Tom's Hardware
Hackers breach OpenAI tapping Claude systems, gaining access to employee accounts and the company's internal codebase
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
A team of white-hat hackers from cybersecurity startup Hackron AI has successfully hacked OpenAI using Claude tools.
Key facts
- The company reportedly fixed the issue within 14 hours of the report and paid the researchers a $6,500 bounty
- From the initial finding to full resolution took 72 hours, after which OpenAI rewarded the researchers with a $6,500 bounty
- The researchers constructed the exploit pipeline using Anthropic's Claude Opus 5 model, after attempts with Opus 4.8 failed
- First, the researchers uploaded a malicious HEIF (High Efficiency Image File) image to the forum as a profile picture
Summary
Operating as hackers under OpenAI’s bug bounty program, Hacktron researchers uncovered critical vulnerabilities that granted them access to internal employee tools and the ability to compromise private software repositories. First, the researchers uploaded a malicious HEIF (High Efficiency Image File) image to the forum as a profile picture. Armed with session tokens hijacked from the local forum server database, the hackers exploited the SSO flaw to impersonate a real OpenAI employee, allowing them to bypass traditional login screens and infiltrate a highly privileged internal account linked to OpenAI's development teams. Similar to an incident last month in which China-linked hackers used AI to carry out the first-ever end-to-end autonomous cyberattack on Taiwan's government, the Hacktron hack also used artificial intelligence.