AI Security4 mins read

Researchers Used Anthropic’s Claude to Hack Into OpenAI, TechCrunch Reports

Security researchers used Anthropic’s Claude during an OpenAI bug-bounty test, chaining vulnerabilities to access employee accounts and an internal code repository before reporting the flaws.

What Happened in the OpenAI Bug-Bounty Test

TechCrunch reports that a three-person security team at Hacktron AI used Anthropic’s Claude as part of an OpenAI bug-bounty program. The researchers chained together two critical vulnerabilities, took over multiple OpenAI employee ChatGPT accounts, and gained access to an internal code repository before reporting the flaws. OpenAI awarded Hacktron AI $6,500 and says it has resolved the issues.

The Vulnerability Path Started With Image Uploads

The researchers found a path into OpenAI through Discourse, the third-party software powering OpenAI’s community forum. According to the report, HEIF or HEIC image uploads passed through ImageMagick and libheif during conversion to JPEG, where a memory bug created an exploitation path. The underlying libheif issue had reportedly been fixed earlier, but was not formally flagged with a CVE, which may have contributed to vulnerable software remaining in use.

Why Claude Opus 5 Mattered

Hacktron said a special version of Claude Opus 4.8 made available to cybersecurity researchers struggled to produce a working exploit. After Anthropic released Opus 5, the team gave it the same problem and said it succeeded within hours. The episode underscores how improvements in model capability can quickly change what is feasible for security researchers—and potentially for attackers.

The Bigger Security Takeaway for AI Labs

The incident lands as AI companies face growing scrutiny over safety, model capabilities, and infrastructure defenses. It shows that even advanced AI companies can be exposed through third-party software, untracked fixes, and connected account access. For security teams, the practical lesson is clear: patch tracking, dependency visibility, and strict account isolation matter more as AI tools reduce the expertise needed to develop exploits.

Discover More

    Google Gemini logo with cybersecurity-themed illustration
    Gemini Test Breakout

    Gemini reportedly reached real company systems during a flawed security test.

    Google GeminiAI Security
    A macro close-up photograph shows the Google Gemini AI app icon
    Gemini’s AI Hacking Test

    Gemini accessed three companies’ protected systems during cybersecurity testing, according to TechCrunch.

    AICybersecurity
    DNA imagery used for TechCrunch article on Anthropic operating a biology lab
    Anthropic’s Biology Lab

    Anthropic is running a wet biology lab while positioning AI for life sciences research and warning about AI risks.

    AnthropicAI
    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping