Sep 18, 2026
ManyPress

Advertisement

Artificial Intelligence

A security team used Anthropic's Claude models to exploit vulnerabilities in OpenAI's community forum, gaining access to internal accounts and code repositories.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:The Decoder
Security Researchers Use Claude AI to Breach OpenAI Internal Systems

Key facts

  • The attack targeted community.openai.com and affected users who utilized the 'Sign in with OpenAI' feature.
  • Researchers proved their access by creating a harmless pull request in OpenAI's internal monorepo using a compromised Codex account.
  • OpenAI confirmed a fix for the vulnerabilities 14 hours after receiving the report from the researchers.
  • The researchers spent less than $3,000 on AI services to conduct the entire project.
  • Only Shopify reportedly detected the researchers' activity during their broader investigation of multiple platforms.

Security researchers from the team Hacktron successfully breached OpenAI's internal systems by exploiting vulnerabilities in the company's community forum. The attack, which took less than 72 hours to execute, allowed the researchers to access employee accounts and an internal GitHub code repository. The team utilized Anthropic's Claude Opus 5 model to develop and refine the exploit, demonstrating the capability of AI to accelerate the discovery and execution of complex cyberattacks.

By the numbers

72 hours
time taken to complete the OpenAI breach
$3,000
total cost spent on AI by the research team
14 hours
time taken for OpenAI to confirm a fix

Vulnerabilities and Attack Method

The researchers chained two specific vulnerabilities to gain access. The first involved a flaw in the libheif library used by the forum to process HEIC images, which allowed the execution of unauthorized code on the server. The second was a misconfiguration in OpenAI's central single sign-on (SSO) system, which enabled the researchers to impersonate forum members and take over their ChatGPT and Codex accounts.

Role of AI in the Breach

The Hacktron team initially struggled to create a reliable exploit using Claude Opus 4.8, specifically when dealing with memory protection defenses like ASLR. However, after the release of Claude Opus 5 on July 24, the model successfully produced a working exploit within three hours. By framing the target as a benchmark task, the researchers enabled the AI to operate in an autonomous loop, taking over the server in four hours.

Broader Security Implications

The project, dubbed 'HEIF Heist,' involved three researchers over two months with a total cost of under $3,000. The team expanded their investigation to include targets such as Slack, Meta, and GitHub Enterprise. Hacktron argues that AI reduces the need for rare human expertise in cyberattacks, allowing complex exploits that previously required significant time and resources to be completed in days.

Timeline

  1. July 24
    Anthropic released the Claude Opus 5 model.
  2. Following July 24
    The researchers used the new model to develop a working exploit within three hours.
  3. Post-report
    OpenAI confirmed the fix for the vulnerabilities 14 hours after the researchers' report.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by The Decoder.

Artificial Intelligence