Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Register
Metaverse Media Group
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
Metaverse Media Group

Security researchers used Anthropic’s Claude to hack OpenAI’s internal systems in under 72 hours

Security researchers used Anthropic’s Claude to hack OpenAI’s internal systems in under 72 hours

The Decoderby The Decoder
18 September 2026
Three security researchers used Anthropic’s Claude models to break into OpenAI’s internal systems through its community forum in less than 72 hours. According to the team, Opus 5 succeeded where its predecessor couldn’t bypass a common security measure. The attack shows how newer AI models can cut the time and expertise needed to exploit security flaws. The article Security researchers used Anthropic’s Claude to hack OpenAI’s internal systems in under 72 hours appeared first on The Decoder….


Matthias Bastian


Sep 18, 2026

Image description

Nano Banana Pro prompted by THE DECODER

Key Points

  • Security researchers used Anthropic’s Claude to break into OpenAI’s internal systems and code repositories.
  • The attack ran through OpenAI’s community forum, where chained vulnerabilities gave the researchers access to employee ChatGPT and Codex accounts.
  • The entire exploit took just 72 hours to develop, showing how drastically AI models are cutting the time and skill needed for sophisticated cyberattacks.

Three security researchers used Anthropic’s Claude models to break into OpenAI’s internal systems through the company’s community forum. The attack took less than 72 hours and, according to the team, only became possible once Opus 5 shipped.

OpenAI is getting a taste of its own medicine. After inadvertently letting agents hack their way across the internet for months, the company has now been hacked with AI’s help. Hacktron’s security team chained two vulnerabilities together to access OpenAI employees’ ChatGPT and Codex accounts. From there, they broke into OpenAI’s internal code repository on GitHub.

The attack ran through OpenAI’s community forum at community.openai.com. Any user or employee who had used “Sign in with OpenAI” there was potentially affected. Users can connect GitHub, Slack, and email to Codex and ChatGPT, so the attack could theoretically have reached those services too. To prove they had access, the researchers used an employee’s Codex account to create a harmless pull request in the internal monorepo. They say they didn’t view any sensitive data.

An outdated image library and flawed authentication opened the door

The first vulnerability was in libheif, the library the forum used to process uploaded HEIC images. According to Hacktron, a fix had been available in the original source code for a year, but no one had flagged it as a security issue. The Debian packages running on the forum still lacked the fix. A crafted image file let the researchers run their own code on the server.

The second vulnerability was a misconfiguration in OpenAI’s central single sign-on (SSO) system. Anyone controlling the forum server could impersonate active forum members and take over their ChatGPT and Codex accounts. The flaw extended beyond the forum, Hacktron writes. Any compromised service using OpenAI login would have granted the same access.

Claude Opus 5 succeeded where its predecessor failed

The researchers say they initially used Claude Opus 4.8 to find the vulnerability. The model built a working exploit, but only with ASLR, a common defense against memory attacks, disabled. Across several sessions, it couldn’t produce a reliable version with ASLR enabled.

On the evening of July 24, Anthropic released Claude Opus 5. According to Hacktron, the new model produced a working exploit for a local Mac within three hours, then adapted it to the Discourse server environment. The researchers then ran Claude in an autonomous loop against their own test instance.

Because the model refused to write exploits against real systems, they presented the target as a benchmark task. Four hours later, the agent had taken over the server. On a related task, the researchers also observed a jump in performance compared to OpenAI’s GPT-5.6 Sol.

OpenAI confirmed the fix about 14 hours after the report. Discourse, the software behind the forum, also responded within days.

AI is making attacks drastically cheaper

Beyond the OpenAI hack, the researchers expanded their investigation, dubbed “HEIF Heist”, to cover Slack, Meta, GitHub Enterprise, and other targets. Three people carried out the project over two months, spending less than $3,000 on AI. Adapting the attack to each new target took just one to two days. Only Shopify noticed the activity, despite thousands of image uploads and repeated crashes in image processing.

Software has long benefited from a kind of security through complexity, the Hacktron team writes. Even with public source code and a known vulnerability, building a reliable exploit required rare expertise, time, and deep knowledge of the target environment. Complexity wasn’t a true security barrier, but it did protect many companies in practice.

AI strips away that protection by replacing scarce expertise with computing power. Hacktron argues that threat models must reflect how cheap attacks have become. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the team writes.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.


Subscribe now

Read the full article on The-Decoder.com
in AI
Reading Time: 4 mins read
0
0
23
VIEWS
Share on TwitterShare on Facebook

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now
ADVERTISEMENT

Related Posts

California Governor Newsom signs executive order demanding “kill switch” for AI models
AI

California Governor Newsom signs executive order demanding “kill switch” for AI models

59 minutes ago
21
XRP Surges 6.9% as Bitcoin Rebound Reopens Door to Golden Cross
AI

XRP Surges 6.9% as Bitcoin Rebound Reopens Door to Golden Cross

2 hours ago
22
AI training built on fair use looks shaky when the companies’ own people call it “astonishing theft”
AI

AI training built on fair use looks shaky when the companies’ own people call it “astonishing theft”

3 hours ago
23

Comments

Please login to join discussion
ADVERTISEMENT

Latest News

  • All
  • Crypto
  • NFTs
  • Technology
  • Business
UAE and Sweden Dismantle $7M Crypto Gang Tied to Contract Hits
Crypto

UAE and Sweden Dismantle $7M Crypto Gang Tied to Contract Hits

Bitcoin.com News
by Bitcoin.com News
14 minutes ago
20
California Governor Newsom signs executive order demanding “kill switch” for AI models
AI

California Governor Newsom signs executive order demanding “kill switch” for AI models

The Decoder
by The Decoder
59 minutes ago
21
Bitcoin Price Hits $81K on Renewed Spot Demand, Leverage Reset
Crypto

Bitcoin Price Hits $81K on Renewed Spot Demand, Leverage Reset

Bitcoin.com News
by Bitcoin.com News
1 hour ago
23
Security researchers used Anthropic’s Claude to hack OpenAI’s internal systems in under 72 hours
AI

Security researchers used Anthropic’s Claude to hack OpenAI’s internal systems in under 72 hours

The Decoder
by The Decoder
1 hour ago
23
XRP Surges 6.9% as Bitcoin Rebound Reopens Door to Golden Cross
AI

XRP Surges 6.9% as Bitcoin Rebound Reopens Door to Golden Cross

Decrypt
by Decrypt
2 hours ago
22
Bitcoin Returns to Inflows With $159M as Zcash ETF Draws $46.6M
Crypto

Bitcoin Returns to Inflows With $159M as Zcash ETF Draws $46.6M

Bitcoin.com News
by Bitcoin.com News
2 hours ago
22
Load More
Next Post
Bitcoin Price Hits $81K on Renewed Spot Demand, Leverage Reset

Bitcoin Price Hits $81K on Renewed Spot Demand, Leverage Reset

ADVERTISEMENT

Follow Us

Categories

  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
Subscribe to our Newsletter

© 2022 Metaverse Media Group – The Metaverse Mecca

Privacy and Cookie Policy | Sitemap

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Sign Up
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Subscribe to our newsletter

Get the latest news & win monthly prizes

Subscribe to our newsletter

For the Latest News and Monthly Prize Giveaways

Join Now
Join Now