OpenAI Hacked by Indian-origin Ethical Hackers Using Anthropic’s Claude AI

Three Indian-origin ethical hackers used Anthropic’s Claude AI to exploit two critical vulnerabilities in OpenAI systems, access internal repositories, and earn a USD 6,500 bug bounty after disclosure.
Anthropic’s Claude AI Beats OpenAI’s ChatGPT in App Store Charts Amid Pentagon Deal Fallout
Written By:
Somatirtha
Reviewed By:
Manisha Sharma
Published on
Updated on

A team of ethical hackers accessed OpenAI’s internal repositories by exploiting two critical vulnerabilities with help from Anthropic’s Claude AI agent. The team, led by three Indian-origin researchers, reported the findings to OpenAI, which later patched the vulnerabilities and awarded them a USD 6,500 (nearly Rs. 6,24,000) bug bounty.

Hackers Exploit Two Critical Vulnerabilities

Researchers from cybersecurity firm Hacktron, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, conducted the hack for research purposes. According to the team, they chained two critical vulnerabilities on July 25 to gain access to ChatGPT accounts of multiple OpenAI employees.

The researchers then gained access to OpenAI’s internal repositories and potentially other connectors. Hacktron said the team reached the internal repositories within 72 hours of discovering the vulnerabilities.

The security flaws were linked to OpenAI’s use of Discourse for its community forum. Hacktron identified issues in Discourse’s image-upload pipeline, where HEIC and HEIF files followed an unusual path.

Anthropic’s Claude Used to Generate Exploit

After Anthropic released its Opus 5 AI model, Hacktron created an exploit and put Claude into an autonomous goal loop against its own Discourse Cloud server.

The AI agent generated an exploit script, which the researchers used to gain remote access to OpenAI’s Discourse Cloud instance. The team then took control of the ChatGPT account of an OpenAI employee whose Codex account was connected to the company’s GitHub.

The incident follows OpenAI’s recent disclosure of an internal AI model that bypassed security controls and accessed the public internet before attacking another AI firm, Hugging Face. The internal model, IM1, gained unauthorized access without being prompted.

Also Read: Anthropic Says Claude Now Leads 26% of Its AI Research Work

OpenAI Patches Vulnerabilities, Pays Bounty

Hacktron reported the vulnerabilities to OpenAI, allowing the company to address the security issues. OpenAI subsequently patched the vulnerabilities that enabled access to its repositories.

The company also rewarded the researchers with a USD 6,500 bounty, roughly equivalent to Rs. 6,24,000. The disclosure underscores the growing role of AI agents in cybersecurity research, including their ability to generate exploit code and help researchers identify vulnerabilities.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp
logo
Artificial Intelligence News & Cryptocurrency News: Latest Trends | Analytics Insight
www.analyticsinsight.net