What's Hot

    Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

    September 19, 2026

    Why Bitcoin hit $80k today hours before bad US data even landed

    September 18, 2026

    Bitcoin faces BOE’s £368 billion QE unwind through 2034

    September 18, 2026
    Facebook Twitter Instagram
    • Business
    • Markets
    • Get In Touch
    • Our Authors
    Facebook Twitter Instagram
    Crypto News: Latest Cryptocurrency News and Analysis
    • Home
    • Business

      Fidelity Buys 7.4% Of Bitcoin Mining Company Marathon Digital Holdings

      February 11, 2021

      Twitter Reacts as Auto Driver Begins Accepting Crypto as Payment

      February 11, 2021

      HSBC Becomes Latest Bank to Suspend Payments to Crypto

      February 4, 2021

      Bitcoin Holds Support; Approaching $50K Resistance

      February 4, 2021

      Cryptocurrency Prices Today: Bitcoin Up Over $47,000, Ether Rises 3%

      February 3, 2021
    • Technology
      1. Business
      2. Insights
      3. View All

      Fidelity Buys 7.4% Of Bitcoin Mining Company Marathon Digital Holdings

      February 11, 2021

      Twitter Reacts as Auto Driver Begins Accepting Crypto as Payment

      February 11, 2021

      HSBC Becomes Latest Bank to Suspend Payments to Crypto

      February 4, 2021

      Bitcoin Holds Support; Approaching $50K Resistance

      February 4, 2021

      Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

      September 19, 2026

      Why Bitcoin hit $80k today hours before bad US data even landed

      September 18, 2026

      Bitcoin faces BOE’s £368 billion QE unwind through 2034

      September 18, 2026

      Bitcoin holds firm after BOJ hike, with Sept. 24 ahead

      September 18, 2026

      Bitcoin Climbs as Elon Musk Says Tesla ‘Likely’ to Accept it Again

      March 16, 2021

      Can Cryptocurrency Be Hacked, Stolen Or Scammed? How Can You Be Safe?

      February 11, 2021

      How Investors Can Get In On Crypto Without Actually Buying Any

      February 4, 2021

      Ethereum Just Underwent a Major Change – Hence, The 25% Jump in a Week!

      February 4, 2021
    • Insights
      1. Bitcoin
      2. Ethereum
      3. Eurozone
      4. Monero
      5. View All

      US Treasury Sanctions Iranian Crypto Exchange Over Alleged IRGC Bitcoin Transfers

      September 18, 2026

      Bitcoin Could See Stronger ETF Demand Than Gold

      September 18, 2026

      SEC Unveils “Innovation Exemption” to Enable Onchain Trading of Tokenised Stocks

      September 18, 2026

      AI Agents Could Put Blockchain Blockspace to the Ultimate Stress Test

      September 18, 2026

      Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

      September 19, 2026

      Why Bitcoin hit $80k today hours before bad US data even landed

      September 18, 2026

      Bitcoin faces BOE’s £368 billion QE unwind through 2034

      September 18, 2026

      Bitcoin holds firm after BOJ hike, with Sept. 24 ahead

      September 18, 2026

      XRP holds $1.30 as falling futures interest signals weak demand

      September 18, 2026

      Ethereum reclaims $2,431 as buyers absorb rate hike and regulatory setback

      September 17, 2026

      XRP recovers but weak derivatives data limits bullish conviction

      September 17, 2026

      Bitcoin holds above key moving averages despite CLARITY Act sell-off

      September 16, 2026

      Green Lantern Comic Art Coin and Medals Revealed by U.S. Mint

      September 18, 2026

      9/11 Half Dollars Lead With 2.28 Million Coins

      September 17, 2026

      US Mint Coin Production Slows as America 250 Rollout Expands

      September 16, 2026

      Five U.S. Coins Top $1 Million in $67.2M Heritage ANA Auctions

      September 15, 2026

      Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

      September 19, 2026

      Why Bitcoin hit $80k today hours before bad US data even landed

      September 18, 2026

      Bitcoin faces BOE’s £368 billion QE unwind through 2034

      September 18, 2026

      Bitcoin holds firm after BOJ hike, with Sept. 24 ahead

      September 18, 2026
    • Markets
    • Get In Touch
    Crypto News: Latest Cryptocurrency News and Analysis
    Home » Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours
    Ethereum

    Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

    行政By 行政September 19, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours.

    Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts.

    One compromised Codex account was connected to OpenAI’s GitHub organization, giving the researchers a path into the company’s internal software environment.

    The team stopped after instructing the compromised employee’s Codex account to create a harmless pull request inside OpenAI’s private openai/openai monorepo. Hacktron said the researchers did not inspect proprietary source code.

    This week, Hacktron disclosed the vulnerabilities and ended further testing.

    OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and later paid the company a $6,500 bounty.

    Anthropic’s Opus 5 cleared a hurdle its predecessor could not

    The OpenAI attack accelerated after Anthropic released Claude Opus 5, which overcame an exploitation hurdle that its predecessor had repeatedly failed to solve.

    Hacktron began examining the image-upload pipeline used by OpenAI’s Discourse community forum on July 23. HEIC and HEIF files were processed through ImageMagick and the underlying libheif decoding library, giving attacker-controlled images a path into vulnerable code.

    The researchers supplied Claude Opus 4.8 with a Discourse Docker image and asked it to inspect the installed libheif package for security weaknesses. The model identified missing fixes that left a heap buffer overflow, enabling out-of-bounds reads and writes.

    By July 24, Opus 4.8 had produced an exploit that achieved code execution when address space layout randomization (ASLR) was disabled. But repeated attempts to make the exploit work reliably against Discourse’s normal configuration with ASLR enabled failed.

    Anthropic released Opus 5 later that day, giving the researchers another route.

    Related Reading

    How a fake AI supercomputer stole $24 million from hundreds of crypto investors

    Hacktron opened a fresh session with the new model, which produced a working ARM64 exploit for a local Mac within about three hours. The researchers then asked it to adapt the exploit to the x86-64 architecture and jemalloc memory configuration used by Discourse.

    By 6 a.m. on July 25, the team had a working exploit that could execute code through a malicious image upload.

    With that foothold established, the researchers next tested whether Claude could reproduce the attack against a remote environment with less human intervention.

    Hacktron placed the model in an autonomous loop against its own Discourse Cloud instance. The company said Claude initially refused to develop an exploit directly against a remote system, prompting the team to proxy the test environment so it resembled a capture-the-flag security challenge.

    Four hours later, the agent had reproduced the attack against the remote test environment.

    The researchers then used the resulting exploit against OpenAI’s community forum, where they gained administrative access. A separate weakness in OpenAI’s single-sign-on system allowed them to move from the forum into ChatGPT and Codex accounts.

    The Catalyst

    What’s moving crypto. Why it matters.

    Get CryptoSlate’s essential stories and what to watch next.

    Published on Substack

    Seven days a week. Unsubscribe anytime.

    Whoops, looks like there was a problem. Please try again.

    Check your inbox.

    Your signup request was sent. If confirmation is required, follow the email from Substack.

    Look in spam or promotions if you don’t see it.

    One compromised employee had connected Codex to OpenAI’s GitHub organization, creating the path the researchers later used to demonstrate access to the company’s internal repository.

    Hacktron co-founder Mohan “s1r1us” Pedhapati said the episode showed how quickly AI was compressing exploit-development timelines that once required far more specialized labor.

    He said:

    “Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable.”

    However, Hacktron stressed that the operation still depended on experienced human researchers. The company noted:

    “This was not completely autonomous hacking, and skilled human guidance remained important.”

    Robert Reith, founder of blockchain security firm Accretion, said experienced researchers still supplied much of the judgment needed to turn AI-generated work into a successful attack, but warned that the advantage may erode as models improve.

    According to him:

    “There’s still a large gap between what skilled researchers + AI can do vs. general population + AI. The scary part is that this gap may become smaller as AI absorbs this knowledge and intuition over time.”

    AI Coding agents expand the blast radius of a compromised account

    The same coding agents that accelerated the exploit also increased its potential reach once the researchers gained control of an OpenAI employee account.

    ChatGPT and Codex can connect to external services, meaning a compromised account may expose whatever integrations a user has authorized. Hacktron cited GitHub, Slack, and email as services that could become reachable, depending on an account’s configuration.

    In this case, the employee’s GitHub connection provided the path into OpenAI’s internal repository.

    Security agents warned that this concentration of permissions around AI coding tools could make them increasingly attractive targets as Codex, Claude Code and similar agents become more deeply embedded in corporate development workflows.

    Codey Blakeney, research lead at Arcee, said:

    “The more popular Codex and Claude Code get, the more people are going to try and target them.”

    Blakeney said the risk could grow if software development becomes concentrated around a small number of AI providers, creating broader points of failure across engineering teams.

    He noted that if regulation moves us to fewer players, it means less choice and more single points of failure. Blakeney added:

    “The entire way software engineering works at most places has completely changed with coding agents, and if just one company has a bad day, it’s going to mess up your roadmap and timelines.”

    Maxime Fournes, CEO of AI safety advocacy group PauseAI, said the breach also highlighted a longstanding imbalance between attackers and defenders that could become more consequential as AI lowers the cost of developing sophisticated exploits.

    According to him, attackers need to find one overlooked weakness, while defenders must secure a much broader attack surface. He noted:

    “It’s massively harder and more expensive to defend against all possible flaws than to exploit a single one.”

    OpenAI tightened access after the disclosure, while Discourse prepared a patch by July 27 and added further sandboxing around its image-processing system.

    AI,Featured,Hacks,Technology#Anthropics #Claude #helped #researchers #breach #OpenAI #hours1789779699

    Anthropics Breach Claude helped Hours OpenAI researchers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    行政
    • Website

    Related Posts

    Why Bitcoin hit $80k today hours before bad US data even landed

    September 18, 2026

    Bitcoin faces BOE’s £368 billion QE unwind through 2034

    September 18, 2026

    Bitcoin holds firm after BOJ hike, with Sept. 24 ahead

    September 18, 2026

    Dtcpay raises $25 million for stablecoin payments

    September 18, 2026
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Millennials Are Quitting Job to Become Day Traders

    January 20, 2021

    Jack Dorsey Says Bitcoin Will Unite The World

    January 15, 2021

    Hong Kong Customs Arrest Four in Crypto Laundering Bust

    January 15, 2021

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo

    Your source for the serious news. This demo is crafted specifically to exhibit the use of the theme as a news site. Visit our main page for more demos.

    We're social. Connect with us:

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

    September 19, 2026

    Why Bitcoin hit $80k today hours before bad US data even landed

    September 18, 2026

    Bitcoin faces BOE’s £368 billion QE unwind through 2034

    September 18, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook Twitter Instagram Pinterest
    • Home
    • Business
    • Markets
    • Technology
    • Contact us
    © 2026 ThemeSphere. Designed by WPfastworld.
    • Easterngifts
    • koreanbj
    • korean bj porn​
    • korean bj nude

    Type above and press Enter to search. Press Esc to cancel.