Company Updates

Claude Opus 5 enabled researchers to exploit OpenAI staff accounts in under 72 hours

Share
Claude Opus 5 enabled researchers to exploit OpenAI staff accounts in under 72 hours

Researchers leveraged Anthropic's Claude Opus 5 to exploit a chain of vulnerabilities, gaining access to OpenAI staff accounts and an internal code repository in under 72 hours. The security firm Hacktron reported the flaws to OpenAI, which confirmed a fix and paid a $6,500 bounty.

TL;DR

  • Researchers used Claude Opus 5 to exploit a chain of vulnerabilities affecting OpenAI's public help forum and login system.
  • The exploit allowed access to OpenAI staff accounts and an internal code repository, demonstrating potential risks of shared single sign-on systems.
  • OpenAI confirmed the fix and paid a $6,500 bounty, highlighting the importance of timely security updates and vigilant bug bounty programs.

What happened

Researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws, taking over the ChatGPT and Codex accounts of several OpenAI employees. This access allowed them to reach an internal OpenAI code repository. The researchers reported the flaws to OpenAI, which confirmed a fix about 14 hours after the report and paid a $6,500 bounty.

The exploit began with a bug in the software running OpenAI's public help forum, which uses Discourse. The forum's image processing tool, ImageMagick, had a vulnerability in the libheif library (CVE-2026-32882) that allowed remote code execution. The researchers combined this with a weakness in OpenAI's login system, which shares single sign-on (SSO) credentials with the forum.

The researchers used Claude Opus 5 to develop a working exploit, demonstrating the model's capability in reducing the time and skill required for such tasks. They emphasized that human direction was still crucial in the process.

Why it matters

This incident highlights the potential risks of shared single sign-on systems, where a vulnerability in one service can compromise others. It underscores the importance of timely security updates and the value of bug bounty programs in identifying and addressing such vulnerabilities.

For developers and startups, this serves as a reminder to regularly update and patch software dependencies, especially those handling untrusted user inputs like images. It also emphasizes the need to limit the scope of single sign-on systems and implement additional security measures for sensitive actions.

For investors, this news underscores the growing importance of AI-assisted security research and the need for companies to prioritize security in their AI development and deployment strategies.

Key facts

  • Researchers used Claude Opus 5 to exploit a chain of vulnerabilities affecting OpenAI's public help forum and login system.
  • The exploit allowed access to OpenAI staff accounts and an internal code repository in under 72 hours.
  • OpenAI confirmed a fix about 14 hours after the report and paid a $6,500 bounty.
  • The vulnerability in libheif (CVE-2026-32882) was patched in libheif 1.22.0 in May 2026, but the forum's server image still shipped the old, unpatched version (1.19.7) when the researchers looked in July.
  • The researchers used Claude Opus 5 to develop a working exploit, demonstrating the model's capability in reducing the time and skill required for such tasks.
  • The exploit was part of a wider project called HEIF Heist, which found similar vulnerabilities in software used by other large companies.
  • OpenAI has not publicly described the login flaw and confirmed the finding through the fix and payment rather than by detailing the account takeovers.

Context

This incident is part of a broader trend where AI models are being used to enhance security research and exploit development. It highlights the need for companies to stay vigilant and proactive in addressing security vulnerabilities, especially those that can be exploited with the help of advanced AI models.

The use of AI in security research is a double-edged sword. While it can help identify and address vulnerabilities more efficiently, it can also be used by malicious actors to develop sophisticated exploits. This underscores the importance of responsible AI development and deployment, as well as the need for robust security measures.

The incident also highlights the importance of bug bounty programs in identifying and addressing security vulnerabilities. By incentivizing researchers to report flaws responsibly, companies can mitigate potential risks and improve the overall security of their systems.

Topics

Related coverage

Join the discussion

Have a take on this story? Weigh in with our community on Facebook.

💬 Discuss on Facebook →