Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • Shark Nebula Image Wins Royal Observatory Greenwich Astronomy Photography Prize
    • Pre-Orders Open for Camp Snap 110 D Screen-Free Digital Camera
    • Researchers Used Claude to Exploit OpenAI Employee ChatGPT Accounts
    • Sigma Unveils 85mm f/1.2 DG Art as Its Fastest Portrait Lens Yet
    • South Park Creators Rename Show ‘South America’ in Apparent Trump Dig
    • UK Shoppers Face Prolonged Food Price Squeeze as Inflation Forecast to Peak at 6.4%
    • ChatGPT Hit by Major Outage as OpenAI Reports Errors and Delays
    • CeX Website Confirms Plans for Retro-Only Games Store in Birmingham
    Mediarun Search
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Technology
    • Sport
    • Entertainment
    • Contact Us
    Mediarun Search
    Home»Business»Researchers Used Claude to Exploit OpenAI Employee ChatGPT Accounts
    Business

    Researchers Used Claude to Exploit OpenAI Employee ChatGPT Accounts

    Edward LangleyBy Edward LangleySeptember 19, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Researchers Used Claude to Exploit OpenAI Employee ChatGPT Accounts
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers used Anthropic’s Claude AI models while investigating vulnerabilities that ultimately allowed them to take control of several OpenAI employees’ ChatGPT accounts, highlighting how advanced AI tools are changing the speed and scale of cybersecurity research.

    The three researchers, from security firm Hacktron, chained together two vulnerabilities and demonstrated that compromised access could extend as far as an internal OpenAI repository. The entire process, from the initial discovery to demonstrating repository access, reportedly took less than 72 hours.

    Researchers Demonstrate OpenAI Account Takeover

    Hacktron researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini said the security issue affected users and OpenAI employees who logged into OpenAI’s community forum.

    “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over,” the researchers said in their write-up. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.”

    The researchers said their investigation began on 25 July through OpenAI’s community forum, which runs on the Discourse platform.

    Image Processing Became the Initial Attack Route

    According to the researchers, the affected Discourse configuration normally relied on FastImage for image checks. However, FastImage did not support HEIF files in the relevant setup.

    As a result, uploaded HEIF images were processed through ImageMagick, which relied on the libheif library before converting the files into another image format.

    “That exposed the underlying libheif parser directly to attacker-controlled files,” the researchers wrote.

    See also  Artificial Intelligence Could Trigger Global Economic Downturn, Bank of England Governor Warns

    The team used Claude Opus 4.8 during its investigation and identified a heap buffer overflow vulnerability in libheif. The researchers initially attempted to develop a remote code execution attack with the model, although that approach did not succeed against Discourse’s default configuration.

    Claude Opus 5 Helped Researchers Develop Working Exploit

    The investigation progressed following the release of Claude Opus 5. The researchers said they used the newer Anthropic model to generate an exploit script that enabled remote code execution on OpenAI’s instance.

    After achieving that level of access, the team said it immediately reported the vulnerability to OpenAI.

    The researchers then demonstrated the potential impact by taking control of an OpenAI employee account whose Codex service was connected to OpenAI’s GitHub organisation.

    “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” they wrote. “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.”

    The harmless pull request was intended to show the potential reach of the compromised account without accessing or extracting OpenAI’s internal source code.

    OpenAI Fixed Vulnerability Within Hours

    According to the researchers, OpenAI fixed the relevant flaw roughly 14 hours after receiving the report. The issue was subsequently marked as resolved, and the Hacktron team received a $6,500 bug bounty.

    OpenAI also clarified that testing against the Discourse-hosted community forum itself fell outside the scope of its bug bounty programme.

    “To clarify the scope of that award: testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program,” OpenAI said in a comment shared by Hacktron. “The award recognizes the OpenAI-side finding, not the actions against Discourse.”

    See also  Britons Flock to Dubai for Luxury Yacht Experiences with Seven Yachts

    Discourse separately issued a fix that introduced image-processing sandboxing and published a security advisory containing patching and rebuilding guidance.

    Neither OpenAI nor Anthropic provided a response to The Register’s requests for comment.

    AI Tools Could Accelerate Cybersecurity Research

    The incident illustrates the growing role of agentic AI systems in security research. Tasks involving vulnerability analysis and exploit development that have traditionally demanded substantial specialist knowledge and time can increasingly be assisted by advanced models.

    In this case, the researchers said the investigation required only several days of AI-assisted work alongside a comparatively small amount of direct human effort.

    “Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said. “Security assumptions must catch up with attacker capabilities.”

    The episode adds to the wider debate over the security implications of increasingly capable AI agents. While such systems can help legitimate researchers identify and report vulnerabilities more quickly, the same capabilities could also change the resources and time required to investigate weaknesses in complex online platforms.

    For technology companies operating interconnected AI services, developer tools and third-party platforms, the research underlines the importance of securing not only individual products but also the authentication and integration pathways connecting them.

    Edward Langley

    Edward Langley is a contributor at Mediarunsearch.co.uk, covering a wide range of topics including news, politics, business, technology, sport, entertainment and lifestyle. He focuses on delivering clear, balanced reporting and useful information that helps readers stay informed about current affairs and developing stories. His work highlights issues, trends and events that matter to everyday audiences, with an emphasis on accuracy, relevance and accessible journalism.

    See also  UK Logistics Firm Enters Administration as Insolvencies Rise Nationwide
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Artificial Intelligence Could Trigger Global Economic Downturn, Bank of England Governor Warns

    September 1, 2026

    RMT announces fresh East Midlands Railway strikes over Aurora train safety concerns

    August 22, 2026

    Flights Delayed at Bristol Airport After Overnight Runway Closure

    August 8, 2026
    Leave A Reply Cancel Reply

    Navigate
    • Home
    • Top News
    • World
    • Economy
    • Science
    • Technology
    • Sport
    • Entertainment
    • Contact Us
    Pages
    • About Us
    • Contact Us
    • DMCA
    • Editorial Policy
    • Privacy Policy
    © 2026 Media Run Search. All Rights Reserved. Designed by Media Run Search.

    Type above and press Enter to search. Press Esc to cancel.