AI News Feed
Market watch
Cybersecurity

Security researchers used Claude to hack into OpenAI, WSJ reports

Hacktron used Claude to breach OpenAI employee accounts and its GitHub Monorepo in under 72 hours, The Wall Street Journal reports.

The team entered through Discourse, the third-party service that hosts OpenAI’s community forums, by exploiting an issue in the system Discourse uses to process HEIF images, according to Hacktron. Hacktron said Claude Opus 5 launched on the evening of July 24, and by 10 a.m. the next day the researchers had used it to achieve remote code execution on Discourse Cloud and access OpenAI’s instance. The Wall Street Journal reported that Monorepo contains what its sources described as “OpenAI’s algorithmic secrets.”

Hacktron described the operation as its HEIF Heist project. The group said it took “only one or two days” to adapt the approach to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using less than $3,000 in tokens. To Hacktron’s knowledge, only one target, Shopify, detected the activity. The vulnerabilities that Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron said OpenAI paid it $6,500 for finding the bug.

Mohan Pedhapati, Hacktron’s chief technology officer, told The Wall Street Journal: “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.” Hacktron is described as a three-person team of independent security researchers.