SyncAI.news, a Varaisys broadcasting
Researchers used Anthropic’s Claude to hack into OpenAI
AM

Aditya Mehta, Rebecca Bellan

· 1 min read

BusinessTechCrunch AI

Researchers used Anthropic’s Claude to hack into OpenAI

In a twist that captures the strange new state of AI security, independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses, The Wall Street Journal reported on Thursday evening.

A three-person security team at startup Hacktron AI carried out the attack as part of an OpenAI bug-bounty program. Hacktron reported its findings to OpenAI, which gave the startup a $6,500 award. The team managed to chain together two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts, which gave them entry into the company’s software.

OpenAI says it has resolved the issues Hacktron uncovered, which happens to come at a moment when top AI companies are under growing pressure over safety.

This incident comes several weeks after OpenAI’s own AI agents broke containment during a cybersecurity evaluation and hacked Hugging Face, demonstrating just how capable AI models are getting at making their own decisions. It also highlights how off-the-shelf technology can be used to find vulnerabilities in even the most advanced companies’ infrastructure.

“For $200 a month, anyone can use these tools and hack into a company like OpenAI,” Matt Fredrikson, CEO of AI security firm Gray Swan, told TechCrunch. “If it can happen to them — and I don’t think they’ve been slouching recently on cybersecurity hygiene —  it could happen to anyone.”

Or as one AI pundit noted on social media: “[Hacktron] used Opus 5 to pull off the hack…The question that will be asked is, if these three guys can pull this off, what can a nation state do.”

The researchers found a path into OpenAI on July 25 via a flaw in Discourse, the third-party software powering OpenAI’s community forum.

Notably, the researchers said the Claude model they were using — a special version of Opus 4.8 made available for cybersecurity researchers — couldn’t build a working exploit at first. That changed overnight, when Anthropic released Opus 5.

View Bio

Original source

This story was published by TechCrunch AI and written by Aditya Mehta, Rebecca Bellan. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on techcrunch.com

Similar News