The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · OpenAI · Anthropic

Researchers used Claude to take over OpenAI employee accounts

A three-person team at Hacktron chained two flaws to reach an internal code repository, and was paid $6,500 under OpenAI's bug bounty.

Security researchers at the startup Hacktron used Anthropic's Claude to exploit two vulnerabilities in OpenAI's systems, taking over employee ChatGPT accounts and reaching an internal code repository, TechCrunch reported on Thursday. They then reported the flaws.

The work was done under OpenAI's bug bounty programme, which pays outside researchers who disclose rather than exploit. OpenAI awarded the three-person team $6,500. The whole sequence, from first discovery to repository access, took under 72 hours.

The detail the researchers emphasised concerns the model rather than the target. They said the version of Claude they had been given, a build of Opus 4.8 released for security researchers, could not assemble a working exploit for the problem.

That changed when Anthropic shipped Opus 5. The team gave the new model the same problem within hours of its release and it produced a working exploit, according to their account. The gap between the two attempts was a matter of days.

Neither company has disputed the account, and OpenAI's payment is a matter of record. CBS News, The Register and Quartz reported the same findings. The researchers' claim about the model generations rests on their own testing and has not been independently reproduced.

Sources 4 sources

  1. Press TechCrunch
  2. Press CBS News
  3. Press The Register
  4. Press Quartz