Claude Code · Anthropic · OpenAI · Claude · GitHub · Codex · CryptoSlate
Anthropic released Opus 5 later that day, giving the researchers another route
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
◎ Multiple-sources
Hacktron opened a fresh session with the new model, which produced a working ARM64 exploit for a local Mac within about three hours.
Key facts
- By July 24, Opus 4.8 had produced an exploit that achieved code execution when address space layout randomization (ASLR) was disabled
- OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and later paid the company a $6,500 bounty
- The researchers supplied Claude Opus 4.8 with a Discourse Docker image and asked it to inspect the installed libheif package for security weaknesses
- By 6 a.m. on July 25, the team had a working exploit that could execute code through a malicious image upload
Summary
01 Claude helped researchers chain two flaws into OpenAI accounts and an internal repository within 72 hours. 02 AI compressed exploit development from months to days, though skilled human guidance remained essential. 03 Connected coding agents concentrate permissions, letting one compromised account expose tools such as GitHub. Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours. Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts.