Researchers Use Anthropic's Claude to Breach OpenAI Systems, Highlighting Rapid Exploitation of Vulnerabilities
Three researchers from Hacktron AI utilized Anthropic’s Claude AI model to exploit two weaknesses, gaining access to OpenAI employee accounts and an internal code repository in under 72 hours. The vulnerabilities were not AI-specific but rather a flaw in third-party forum software and a configuration error allowing session tokens to remain valid across OpenAI services. The researchers privately disclosed their findings, leading OpenAI to patch the single sign-on flaw within approximately 14 hours and pay a $6,500 bounty. This incident, while a successful bug bounty process, underscores how AI can accelerate the exploitation of existing vulnerabilities. The researchers noted that switching to a newer Claude model allowed them to develop a working exploit within hours, completing the full chain in less than three days.