A lot has been happening in the AI world lately.
Several AI leaders have publicly argued that AI development needs to slow down. Just yesterday, OpenAI published a report detailing six concerning AI safety incidents it discovered over the past six months, warning that the industry hasn't solved AI alignment well enough to keep scaling models at maximum speed.
Now there's another incident.
Three security researchers say they broke into OpenAI — and, ironically, they used Anthropic's Claude to help do it. The twist is hard to ignore because OpenAI's own models were recently caught hacking Hugging Face during a security test just a few weeks ago.
OpenAI ended up paying the researchers $6,500 through its bug bounty programme, where companies reward ethical hackers for responsibly disclosing security flaws before malicious actors can exploit them.
How the breach happened
The three researchers from Hacktron AI exploited a vulnerability in OpenAI's community forum, which is hosted on the third-party platform Discourse.
According to the researchers, they obtained authentication tokens that also worked across ChatGPT and OpenAI's GitHub infrastructure. Some of those tokens belonged to OpenAI employees and provided access to the company's Monorepo — a repository containing proprietary AI software and internal code.
"We're just three guys with Claude and Codex subscriptions," said Mohan Pedhapati, Hacktron AI's CTO.
He added that they don't consider themselves anywhere near as capable as state-backed hacking groups, including Chinese threat actors.
The researchers reported the vulnerability immediately, and OpenAI patched the issue after verifying their findings.
OpenAI's response
OpenAI confirmed the incident and said it had already tightened its security.
"We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions."
Subscribe for free to continue reading this article
Subscribe SubscribeAlready have an account? Log in