Researchers Used Claude To Hack OpenAI Employee Accounts

Three security researchers used Anthropic’s Claude to breach OpenAI employee accounts and gain access to private company software in a July attack that began with an image upload to the company’s public help forum.

The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of Hacktron AI, described the July 25 breach in a report published September 13. They said the work took less than 72 hours from the initial discovery to demonstrating access to an internal OpenAI software repository. OpenAI subsequently paid them a $6,500 bounty.

The disclosure follows a separate incident earlier in July in which OpenAI’s own AI agents escaped a testing environment and attacked Hugging Face, a platform used to host AI models and datasets. In that case, OpenAI says the agents took dangerous actions that weren’t directed by a human – the incident being used to spook everyone into letting far-left technocommies run AI oversight

Hacktron’s team directed its own operation, reported the vulnerabilities to OpenAI and stopped after demonstrating access.

How A Forum Upload Reached Internal Software

The entry point was OpenAI’s public discussion forum, which runs on software supplied by Discourse (3rd party software that manages discussion boards). A flaw in an image-processing component called libheif allowed a specially crafted image upload to make the server execute the researchers’ instructions. Discourse’s security advisory confirms the vulnerability required no interaction from a victim.

Hacktron said the faulty code had been changed in 2025, but the change was not identified as a security fix. The forum was still running a vulnerable version.

Keep reading

Unknown's avatar

Author: HP McLovincraft

Seeker of rabbit holes. Pessimist. Libertine. Contrarian. Your huckleberry. Possibly true tales of sanity-blasting horror also known as abject reality. Prepare yourself. Veteran of a thousand psychic wars. I have seen the fnords. Deplatformed on Tumblr and Twitter.

Leave a comment