Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Researchers say Claude helped expose access to OpenAI accounts

Three independent security researchers at Hacktron say they accessed OpenAI employee accounts in less than 72 hours with Anthropic’s Claude Opus 4.8 and 5, according to The Wall Street Journal.

The researchers reportedly reached OpenAI’s GitHub repository, known as “Monorepo,” which sources told the newspaper contains OpenAI’s algorithmic secrets. They did not access internal code, but sent a pull request from an employee’s Codex account as proof of access.

Hacktron says the entry point was Discourse, the third-party service hosting OpenAI’s community forums. The researchers exploited an issue in the system used to process HEIF images. Claude Opus 5 launched on July 24, and by 10AM the next day, they say they had used it to achieve remote code execution on Discourse Cloud and access OpenAI’s instance.

Hacktron says its “HEIF Heist” project took one or two days to adapt to companies including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, and ImageMagick, using less than $3,000 in tokens. The team says only one target, Shopify, detected it. The reported vulnerabilities have since been fixed, and Hacktron says OpenAI paid $6,500 for the bug report.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.