11:51
17:09
15:00
18:32
17:13
15:20
11:51
17:09
15:00
18:32
17:13
15:20
11:51
17:09
15:00
18:32
17:13
15:20
11:51
17:09
15:00
18:32
17:13
15:20
A three-person team at Hacktron AI used Anthropic’s Claude to break into OpenAI’s community forum and gain access to employees’ ChatGPT accounts, The Wall Street Journal reported.
In its technical account, Hacktron says the team then used one employee’s Codex account to open a harmless test pull request in OpenAI’s private code repository. The researchers say they reached that point less than 72 hours after finding the initial vulnerability.
The breach involved two separate weaknesses:
Hacktron says an earlier version of Claude identified the image-processing weakness but could not make the exploit reliable. Claude Opus 5 helped produce a working version.
Hacktron reported both flaws in July. OpenAI told Business Insider that it narrowed permissions on community sign-in tokens and revoked affected tokens and sessions. OpenAI paid Hacktron $6,500 for the flaw in its own sign-in system.

