Researchers use Anthropic’s Claude to access OpenAI internal systems
A cybersecurity team that discovered a security vulnerability in a system used by artificial intelligence company OpenAI managed to gain access to some of the company’s internal systems using Anthropic’s Claude software.
The cybersecurity team at Hacktron AI, a company that identifies and reports vulnerabilities in the digital infrastructure of major organizations, discovered a software flaw in an online discussion forum used by OpenAI, CE Report quotes Anadolu Agency.
According to statements shared by the researchers and reports in the U.S. media, the researchers used Anthropic’s Claude model to exploit the vulnerability in the discussion forum and gained access, through authentication systems obtained during the process, to the accounts of some OpenAI employees and the company’s software repository.
After reporting their findings to OpenAI, the researchers received a monetary reward from the company.
The researchers said the “controlled attack” demonstrated that state-sponsored actors and other highly capable cyber operators could potentially gain access to sensitive information related to a country’s artificial intelligence sector.
Mohan Pedhapati, chief technology officer of Hacktron AI, said the team did not consider itself as capable as Chinese cyber actors.
“We’re just three people with Claude and Codex subscriptions,” he said.
How did they succeed?
The researchers discovered a flaw in the way OpenAI’s discussion forum processed certain image files. They then gained access to a specialized version of Claude Opus 4.8 made available to qualified cybersecurity researchers and asked the model to write code capable of exploiting the vulnerability in a cyberattack.
The version initially failed to exploit the flaw. However, Anthropic released Opus 5 later that evening, and the following day Claude found a way to exploit the vulnerability.
The attack code generated by Claude allowed the researchers to access the server hosting OpenAI’s discussion forum. From there, they gained access to authentication systems that enable users to access online services.
The researchers determined that these authentication systems could also be used to access OpenAI’s GitHub software repository. They also found that some of the credentials were valid for ChatGPT and belonged to OpenAI employees.
After realizing that they could potentially access sensitive internal data, the researchers stopped short of accessing confidential code. Instead, using a single employee account, they submitted a “harmless change” request to OpenAI’s internal code repository.
The researchers submitted the request as evidence that they had gained access to OpenAI’s systems and reported the vulnerability to both OpenAI and Discourse, the company that develops the software used by OpenAI’s discussion forum.
Following the report, OpenAI said the vulnerability had been fixed and awarded the research team $6,500.
“We thank the researchers for contacting us and sharing their findings. We have restricted the permissions of login tokens on the community forum and revoked the affected tokens and sessions,” OpenAI said.
An Anthropic spokesperson declined to comment when approached by the newspaper.
A token is a digital asset or unit of data used on a blockchain.
Photo: Chat GPT









