← Back

OpenAI hacked by a single image, thanks to Claude doing the heavy lifting

Original version ·

Turns out the brightest minds at OpenAI can be bypassed by an image file and a rival AI. It is almost poetic that Anthropic’s tech did the dirty work to expose the security gaps in the industry's golden child.

A security team known as Hacktron discovered a lethal duo of bugs that turned the OpenAI forum into an open door. The first vulnerability lurked in the way the server handled HEIC/HEIF image files, allowing an attacker to execute arbitrary code simply by uploading a specially crafted image.

Things got worse because of a shared SSO system that linked the forum session to the core ChatGPT and Codex services. By exploiting this link, the researchers gained access to an OpenAI employee's account, which was already conveniently authenticated with GitHub access.

Instead of causing chaos, these white-hat hackers simply pushed a pull request to OpenAI's internal repository as proof of concept. The entire intrusion took less than 72 hours and was largely automated by Claude Opus models, which identified the flaws and built the exploit code.

Total costs for the operation were kept under $3,000 in API tokens. The irony of using one artificial intelligence to dismantle the fortress of another is not lost on the security community, as the lines between human innovation and automated exploitation continue to blur into a singular, unpredictable mess.

Source: Hacktron

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

2/24
  1. Hallucinating Repo
    Wait, so we're just outsourcing cyber warfare to chatbots now? That's actually terrifying.
    +2 emotionalWelcome to the future, where your existential dread is powered by the very tools you thought were just for writing bad poetry