00:00
Tech and Rich
Tech and Rich
USD/RUB
EUR/RUB
Technology

Hackers breached OpenAI internal systems using Claude AI

Three independent researchers from Hacktron bypassed OpenAI’s security perimeter in under 72 hours, leveraging Anthropic’s Claude Opus models to exploit a vulnerability in the Discourse forum platform. The breach granted them access to sensitive GitHub repositories, proving that sophisticated AI tools can dramatically accelerate the discovery of complex software flaws.

Hackers breached OpenAI internal systems using Claude AI

The team targeted the company’s internal GitHub repository, known as Monorepo, which houses critical algorithmic secrets. While the researchers refrained from downloading proprietary code, they successfully submitted a pull request from a compromised employee Codex account to verify their access. The intrusion originated through a flaw in the HEIF image processing system used by Discourse, the third-party service hosting OpenAI’s community forums. Claude Opus 5 played a pivotal role in the operation; after its launch on the evening of July 24, the team achieved remote code execution on Discourse Cloud by the following morning.

This project, dubbed HEIF Heist, demonstrated the scalability of AI-assisted exploits. The researchers adapted their methods to target Slack, Meta, GitHub, and other major platforms in less than 48 hours with a budget of under $3,000. Despite the breadth of these attempts, only Shopify identified the intrusion. Following the disclosure, the vulnerabilities were patched, and OpenAI issued a $6,500 bug bounty. Hacktron CTO Mohan Pedhapati noted that the ease of the attack suggests a shifting landscape where small teams can replicate the capabilities of state-sponsored threat actors using consumer-grade AI subscriptions.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!