Particle.news
Download on the App Store

White‑Hat Team Used Anthropic’s Claude to Breach OpenAI Systems

Experts say the test shows agentic models can rapidly create exploits, requiring companies to tighten controls, limit special‑access model use, and adopt identity‑scoped credentials.

Overview

  • A three‑person Hacktron security team ran a special, authorized variant of Anthropic’s Claude Opus 5 to chain a HEIF image‑processing bug in libheif/ImageMagick with an OpenAI single‑sign‑on flaw and gain access to employee ChatGPT and Codex accounts.
  • Using a connected Codex account the researchers opened a harmless pull request in OpenAI’s private openai/openai repository to prove access, then stopped testing and reported the issues through OpenAI’s bug‑bounty process.
  • OpenAI patched the SSO/token flaw and narrowed or revoked affected community sign‑in tokens and sessions within about 14 hours, and Hacktron received a $6,500 bounty for the submission.
  • Hacktron said the automated exploit development ran in an autonomous loop, cost under $3,000 in token credits and took less than 72 hours to complete after Anthropic released Opus 5, which succeeded where Opus 4.8 failed.
  • The underlying HEIF/libheif weakness touches many vendors including Slack, Zoom, Meta, GitHub Enterprise and Ruby on Rails, and the case has renewed industry calls for stronger sandboxing, short‑lived scoped credentials, pre‑release exploit testing and tighter governance of special‑access models.