Hacktron AI Claims Three-Person Team Breaches OpenAI Codebase in Under 72 Hours Using Claude-Assisted Attack
Summary
Hacktron AI says a three-person team breaches OpenAI’s private codebase in under 72 hours using a Claude-assisted attack, exploiting an image-upload flaw and staff sign-in tokens before leaving a signed internal-document edit and collecting a $6,500 bug bounty.
Key Points
- Hacktron AI says its three-person team breaches OpenAI’s private codebase in under 72 hours, taking over employee accounts with an attack partly written by Anthropic’s Claude.
- The researchers exploit an image-upload flaw in OpenAI’s community forum, then use a second vulnerability to turn staff sign-in tokens into access to ChatGPT accounts.
- Hacktron leaves a signed edit in an internal OpenAI documentation file as proof, reports the flaws, and receives a $6,500 bug bounty.