Related News

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

October 22, 2025
Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

April 10, 2026
Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

June 18, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

Related News

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

October 22, 2025
Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

April 10, 2026
Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

June 18, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
CONTRIBUTE
WEMAPLE NEWS - Brand Partnerships
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news
No Result
View All Result
WEMAPLE NEWS - Brand Partnerships
No Result
View All Result
Home Crypto

Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

WeMaple AI by WeMaple AI
September 19, 2026
in Crypto
0
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours.

You might also like

CFTC Submits Secret Two-Part Crypto Rules Package to White House

Bitcoin faces an eight-year rates test as the BOE unwinds £368 billion

Bitcoin rallies after BOJ’s 1.25% hike, but the real yen-carry test starts next week

Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts.

One compromised Codex account was connected to OpenAI’s GitHub organization, giving the researchers a path into the company’s internal software environment.

The team stopped after instructing the compromised employee’s Codex account to create a harmless pull request inside OpenAI’s private openai/openai monorepo. Hacktron said the researchers did not inspect proprietary source code.

This week, Hacktron disclosed the vulnerabilities and ended further testing.

OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and later paid the company a $6,500 bounty.

Anthropic’s Opus 5 cleared a hurdle its predecessor could not

The OpenAI attack accelerated after Anthropic released Claude Opus 5, which overcame an exploitation hurdle that its predecessor had repeatedly failed to solve.

Hacktron began examining the image-upload pipeline used by OpenAI’s Discourse community forum on July 23. HEIC and HEIF files were processed through ImageMagick and the underlying libheif decoding library, giving attacker-controlled images a path into vulnerable code.

The researchers supplied Claude Opus 4.8 with a Discourse Docker image and asked it to inspect the installed libheif package for security weaknesses. The model identified missing fixes that left a heap buffer overflow, enabling out-of-bounds reads and writes.

By July 24, Opus 4.8 had produced an exploit that achieved code execution when address space layout randomization (ASLR) was disabled. But repeated attempts to make the exploit work reliably against Discourse’s normal configuration with ASLR enabled failed.

Anthropic released Opus 5 later that day, giving the researchers another route.

Related Reading

How a fake AI supercomputer stole $24 million from hundreds of crypto investors




Hacktron opened a fresh session with the new model, which produced a working ARM64 exploit for a local Mac within about three hours. The researchers then asked it to adapt the exploit to the x86-64 architecture and jemalloc memory configuration used by Discourse.

By 6 a.m. on July 25, the team had a working exploit that could execute code through a malicious image upload.

With that foothold established, the researchers next tested whether Claude could reproduce the attack against a remote environment with less human intervention.

Hacktron placed the model in an autonomous loop against its own Discourse Cloud instance. The company said Claude initially refused to develop an exploit directly against a remote system, prompting the team to proxy the test environment so it resembled a capture-the-flag security challenge.

Four hours later, the agent had reproduced the attack against the remote test environment.

The researchers then used the resulting exploit against OpenAI’s community forum, where they gained administrative access. A separate weakness in OpenAI’s single-sign-on system allowed them to move from the forum into ChatGPT and Codex accounts.

One compromised employee had connected Codex to OpenAI’s GitHub organization, creating the path the researchers later used to demonstrate access to the company’s internal repository.

Hacktron co-founder Mohan “s1r1us” Pedhapati said the episode showed how quickly AI was compressing exploit-development timelines that once required far more specialized labor.

He said:

“Our main takeaway from hacking OpenAI: AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days. Even leading AI labs can be vulnerable.”

However, Hacktron stressed that the operation still depended on experienced human researchers. The company noted:

“This was not completely autonomous hacking, and skilled human guidance remained important.”

Robert Reith, founder of blockchain security firm Accretion, said experienced researchers still supplied much of the judgment needed to turn AI-generated work into a successful attack, but warned that the advantage may erode as models improve.

According to him:

“There’s still a large gap between what skilled researchers + AI can do vs. general population + AI. The scary part is that this gap may become smaller as AI absorbs this knowledge and intuition over time.”

AI Coding agents expand the blast radius of a compromised account

The same coding agents that accelerated the exploit also increased its potential reach once the researchers gained control of an OpenAI employee account.

ChatGPT and Codex can connect to external services, meaning a compromised account may expose whatever integrations a user has authorized. Hacktron cited GitHub, Slack, and email as services that could become reachable, depending on an account’s configuration.

In this case, the employee’s GitHub connection provided the path into OpenAI’s internal repository.

Security agents warned that this concentration of permissions around AI coding tools could make them increasingly attractive targets as Codex, Claude Code and similar agents become more deeply embedded in corporate development workflows.

Codey Blakeney, research lead at Arcee, said:

“The more popular Codex and Claude Code get, the more people are going to try and target them.”

Blakeney said the risk could grow if software development becomes concentrated around a small number of AI providers, creating broader points of failure across engineering teams.

He noted that if regulation moves us to fewer players, it means less choice and more single points of failure. Blakeney added:

“The entire way software engineering works at most places has completely changed with coding agents, and if just one company has a bad day, it’s going to mess up your roadmap and timelines.”

Maxime Fournes, CEO of AI safety advocacy group PauseAI, said the breach also highlighted a longstanding imbalance between attackers and defenders that could become more consequential as AI lowers the cost of developing sophisticated exploits.

According to him, attackers need to find one overlooked weakness, while defenders must secure a much broader attack surface. He noted:

“It’s massively harder and more expensive to defend against all possible flaws than to exploit a single one.”

OpenAI tightened access after the disclosure, while Discourse prepared a patch by July 27 and added further sandboxing around its image-processing system.

The post Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours appeared first on CryptoSlate.

Read Entire Article
Tags: CryptoCryptoslate
Share30Tweet19
WeMaple AI

WeMaple AI

Recommended For You

CFTC Submits Secret Two-Part Crypto Rules Package to White House

by WeMaple AI
September 18, 2026
0
CFTC Submits Secret Two-Part Crypto Rules Package to White House

The post CFTC Submits Secret Two-Part Crypto Rules Package to White House appeared first on Coinpedia Fintech News The US Commodity Futures Trading Commission (CFTC) has today submitted...

Read more

Bitcoin faces an eight-year rates test as the BOE unwinds £368 billion

by WeMaple AI
September 18, 2026
0

Gilt yields fell as active auctions paused, yet the Bank’s full portfolio unwind keeps a slow-burn rates risk alive The post Bitcoin faces an eight-year rates test as...

Read more

Bitcoin rallies after BOJ’s 1.25% hike, but the real yen-carry test starts next week

by WeMaple AI
September 18, 2026
0

The yen weakened after the decision, leaving immediate unwind pressure limited as higher funding costs move toward implementation The post Bitcoin rallies after BOJ’s 125% hike, but the...

Read more

Why SBI just put millions behind a Singapore startup’s stablecoin push

by WeMaple AI
September 18, 2026
0

The Singapore firm plans merchant, enterprise-portal and app expansion as SBI joins the Vertex-led round The post Why SBI just put millions behind a Singapore startup’s stablecoin push...

Read more

FCA draws the UK boundary for offshore crypto platforms ahead of 2027 rules

by WeMaple AI
September 18, 2026
0

Direct consumer access and agency trading can bring offshore services within scope when the rules begin in October 2027 The post FCA draws the UK boundary for offshore...

Read more

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

XRP Treasury: SBI Holdings Leads $200M Investment in Evernorth

October 22, 2025
Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

Trump Memecoin Event Fine Print Says He May Not Show Up — Senators Want Answers

April 10, 2026
Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

Over 1M abortions took place in US last year; telehealth abortions fuel increase: report

June 18, 2026

Browse by Category

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news
WEMAPLE NEWS – Brand Partnerships

Wemaple will be firmly committed to the public interest and democratic values.

CATEGORIES

  • Canadian news feed
  • Crypto
  • Faith
  • Geothermal
  • Golf news
  • Hockey news
  • Running & fitness
  • Skateboarding
  • Sports & Fitness
  • WeMaple news

BROWSE BY TAG

AZO Clean Tech Bitcoinist Bitcoinmagazine Canada News CBC.ca Celebrity News Christian Post CoinPedia Corporate Knights Crypto Cryptoslate Faith Geothermal Golf Hockey Lifehacker Ludwig-van.com NcrOnline newsbtc Skateboarding tomsguide.com Utah news dispatch

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.

No Result
View All Result
  • Home
  • Canadian news feed
  • Skateboarding
  • Sports & Fitness
    • Golf
    • Hockey
    • Running & fitness
  • Faith
  • Geothermal
  • Crypto
  • WeMaple news

© 2025 wemaple.canadiana.news - all rights reserved. YYC TECH CONSULTING.