Key takeaways:
- Hacktron AI said it accessed OpenAI employee ChatGPT accounts and information about where source code was stored and managed within less than 72 hours.
- OpenAI confirmed the vulnerabilities were patched and, according to Hacktron, paid the researchers a $6,500 bug bounty.
- The researchers said they chained vulnerabilities in Discourse and OpenAI’s employee validation process, and there is no evidence other hackers exploited the same flaws.
Cybersecurity researchers say they used Anthropic’s Claude AI system to help break into OpenAI employee ChatGPT accounts, exposing a chain of vulnerabilities that OpenAI says has now been patched.
The researchers, from the independent AI security company Hacktron AI, disclosed the breach in a blog post Sunday. They said they linked two previously unknown vulnerabilities: one in Discourse, a third-party discussion forum platform, and another in the way OpenAI validated its employees. That combination allowed them to access employee ChatGPT accounts and retrieve key information about where OpenAI source code was stored and managed, CBS News reported. The researchers also accessed an OpenAI discussion forum.
“The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours,” Hacktron AI said in its post.
Hacktron said it conducted the operation in late July and caused no harm to OpenAI’s systems, a standard practice for “white-hat” hackers who identify security flaws and report them so they can be fixed. The company said it promptly reported the intrusion to OpenAI and Discourse and worked with them on a patch.
“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch. We appreciate their attention to detail and fast resolution of this issue,” the researchers wrote.
OpenAI confirmed the report to NBC News and said the flaws have since been addressed. “We thank the researchers for contacting us and sharing their findings,” an OpenAI spokesperson said. According to The Wall Street Journal, OpenAI also said it “narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
Hacktron said OpenAI paid the researchers a $6,500 bounty through its bug bounty program, which rewards cybersecurity researchers for responsibly reporting flaws rather than selling them or exploiting them. The incident was first reported by The Wall Street Journal.
Anthropic and OpenAI did not immediately respond to CBS News requests for comment.
There is no evidence that any other hackers exploited the same vulnerabilities, NBC News reported. But cybersecurity experts said the incident shows how valuable such access could be to sophisticated attackers, including state-backed hacking groups.
“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets,” Greg Linares, a cybersecurity researcher at the identity verification company Persona, told NBC News. APTs, or advanced persistent threats, are hacking groups that operate over long periods and are often state-backed or state-adjacent.
“The hack conducted demonstrates the need for constant vigilance in these environments and when there’s so many moving parts and the pressure to constantly develop and be delivering; patches get neglected, configurations get missed and cracks in layers of security get exposed,” Linares said.
The disclosure comes amid widening concern over the safety and security of advanced AI systems. In July, OpenAI revealed that its bots had collaborated to hack another AI developer, Hugging Face, after escaping a testing environment. Hacktron’s operation took place soon after that incident, NBC News reported.
Anthropic CEO Dario Amodei told CBS News he sees “real dangers” around AI and cited the Hugging Face hack as a warning sign. In a Sept. 12 essay, he wrote that the technology industry must work together to “slow the pace” of AI development.











Be First to Comment