White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours and it is a case study in just how fast AI is advancing
Date:
Fri, 18 Sep 2026 10:49:48 +0000
Description:
The researchers struggled to abuse the exploit with an AI agent on Opus 4.8, but the release of Opus 5 changed everything.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Security researchers used
Claude Opus 5 to hijack an OpenAI employee's ChatGPT account Exploit abused
an image processing flaw on OpenAI community forums to gain full repo access The entire timeline from vulnerability discovery to repo access took less
than 72 hours While taking part in an OpenAI bug bounty program, a group of Hacktron security researchers managed to compromise an internal OpenAI
ChatGPT account and access internal company code on Github.
According to the Wall Street Journal , who first reported the incident, the researchers used a special version of Anthropics Claude made available to qualified cybersecurity practitioners to pull off the attack. The researchers initially attempted to use Claude Opus 4.8 to create a breach, but faced multiple setbacks as the model struggled across several sessions to produce a working exploit. But the release of Opus 5 changed everything. Latest Videos From TechRadar Watch full video here: OpenAI breach part of wider libheif exploit The breach started with a libheif exploit that abuses a flaw in the .heic/.heif/.avif image file format decoder and encoder. While this exploit allowed Hacktron to breach OpenAI, libheif is also used across other
platforms and software including Slack, Meta, GitHub Enterprise, Ruby on Rails, and more.
To start, the researchers first noted that the OpenAI community forum relies on the Discourse platform, which in turn relies on FastImage for image
checks. But FastImage does not support .heif image files, and these are
passed on to ImageMagick for conversion instead. You may like Anthropic reveals Claude AI model hacked three companies during tests so how worried should we be? OpenAI says its models escaped a sandbox and breached Hugging Face Claude Cowork can break its bonds and access Mac files, experts claim
Developing a working code-execution exploit that abused this relation between ImageMagick and libheif with Opus 4.8 wasnt fruitful, the researchers said, but on the same day Anthropic released Claude Opus 5.
With Opus 5, the researchers managed to create a working local remote code execution (RCE) using the same premise by setting an AI agent in a loop to exploit a local Discourse Cloud instance. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
The successful Discourse exploit was then used against the OpenAI community forums, where the researchers hijacked an OpenAI employees ChatGPT account. The employee had connected their ChatGPT Codex with the companys Github, allowing the researchers full repo access. Exploit needed just a few hours of human interaction Where the researchers spent hours struggling to create a working exploit with Opus 4.8, the release of Opus 5 showed that every new model is getting increasingly capable." It took the agent running on Opus 5 just a few hours to develop a working exploit.
The full timeline from initial discovery of the exploit to OpenAI repo access took just 72 hours, researchers noted. What to read next OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff AI agents organized into a swarm, considered the risks of attack, and did whatever it took to achieve its goal A newbie hacker used "vague, low-skill prompts" in Claude and Codex to breach 14 companies, and the AI Agents did all the
legwork Experts explain why OpenAI's 'mind-blowing' cyberattack should worry us all
The researchers also said that the entire OpenAI and Discourse hack took a
few days for an agent, and just a few hours of human time in order to be successful. Furthermore, their research into the libheif exploit against organizations such as Slack, Zoom, Meta took two-months, cost less than
$3,000 in tokens in total, and was conducted by three researchers.
The AI started almost blind and adapted the exploit for each company within one or two days, the researchers said. We are not aware of any company that detected the activity except Shopify, even after thousands of images were
sent and their image processors repeatedly crashed.
In return for exposing the vulnerabilities, Hacktron was awarded a $6,500 bounty from OpenAI, and the libheif vulnerability has been patched. AI agents are the future, for better or for worse
There's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it? Spencer Starkey, SonicWall Hacktron's exploit demonstration shows how prevalent AI agents are becoming in cybersecurity. Where they have been lauded by AI companies to provide productivity bonuses and efficiency increases to workers, the same can be said for attackers.
The fact that it took just 72 hours from exploit discovery to full repo
access highlights the dangers. By setting an AI agent to run on a continuous loop until it creates a workable exploit dramatically shifts the exploit timeline from weeks or months in the case of non-AI assisted attacks to mere hours for attackers aided by agents.
This is a similar circumstance to OpenAI's own accidental breach of Hugging Face during testing of AI agents . The agents were essentially told to complete a test scenario by any means necessary, which the agents interpreted as permission to go beyond their alignment and hack into a third-party environment that they thought held the key to solving their task.
"AI has been changing the threat landscape for a while now, and the defence landscape with it," Spencer Starkey, Executive VP EMEA at SonicWall said.
"But there's a conversation we're not having loudly enough: do you actually want your security platform to have been built by AI, with no human track record behind it?"
"It looks compelling. You have low cost, high margins, slick interface. But what happens when something goes wrong at 02:00 in the morning and you need someone who knows the product, knows your environment, and has seen that problem before? An AI-built platform with zero employees can't give you that.
"Why go with an established vendor when a newer option does 90% of the same things for half the price? It's a fair question. But the 10% you're trading away is usually accountability, resilience, and institutional knowledge. Exactly what matters most when you're under attack.
"It looks like due diligence is eroding, and that worries me. Shiny and affordable is a powerful combinationfor magpies. But in cyber security, the cost of a bad supplier decision doesn't show up until the moment you can
least afford it, so dont be a magpie," Starkey concluded. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/white-hat-hackers-just-breached-openai- using-anthropics-claude-in-less-than-72-hours-and-it-is-a-case-study-in-just-h ow-fast-ai-is-advancing
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)