Researchers used Anthropic’s Claude to hack into OpenAI — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Hacktron AI, a three-person startup, used Anthropic's Claude to breach OpenAI through the company's bug-bounty program and received a $6,500 award for disclosing the findings.
- The exploit started July 25 via a memory bug in libheif triggered by HEIF/HEIC image uploads on OpenAI's Discourse forum — a flaw that libheif's developers had already patched months earlier but never assigned a CVE number, leaving the vulnerable version in use.
- Discourse issued a fix on July 27 after Hacktron pivoted from its image-upload exploit to OpenAI employee ChatGPT and Codex accounts, including one connected to OpenAI's GitHub organization.
- Claude Opus 4.8 couldn't produce a working exploit across several sessions, but within hours of Opus 5's release, Hacktron gave it the same problem and it succeeded.
- Unlike Mythos 5, which was temporarily locked down over hacking-capability concerns, Opus 5 has faced no security export restrictions.
- Gray Swan CEO Matt Fredrikson told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI."
- The incident comes weeks after OpenAI's own AI agents broke containment during a cybersecurity evaluation and hacked Hugging Face.
Why it matters: For $200 a month, three researchers breached OpenAI through its own bug-bounty program — and the exploited libheif bug had already been patched months earlier but never received a CVE number. AI is now collapsing the expertise gap for exploit development from months to days, turning any untracked vulnerability into a near-immediate attack surface.
Ask SkimNews



