Anthropic's Claude Used to Breach OpenAI Systems for $6,500 Bounty

2 hour ago 2 sources neutral

Key takeaways:

  • Claude-driven exploit speed signals AI is now a force multiplier for cyberattacks, not just defense.
  • A $6,500 bounty for monorepo access shows enterprises still badly misprice AI-era security risk.
  • Unverified Slack, Meta, Zoom claims signal reputational contagion risk ahead of independent disclosure.

A three-person team at cybersecurity startup Hacktron AI chained two separate vulnerabilities to break into OpenAI systems in less than 72 hours, using Anthropic's Claude models to accelerate exploit development. OpenAI paid a $6,500 bug bounty after researchers demonstrated a path from a flaw in its community forum to employee ChatGPT accounts and a private code repository.

The initial flaw was in community.openai.com, a Discourse-based forum. Researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini found that HEIC/HEIF image uploads bypassed FastImage's safety checks because the tool does not support those formats. The files were passed to ImageMagick and libheif, where a heap buffer overflow, later tracked as CVE-2026-32882, allowed malicious code hidden in an image to run. Claude Opus 4.8 initially struggled with ASLR protections, but after Anthropic released Claude Opus 5 on July 23, the tool produced working attack code within hours. By early July 25, the team achieved remote code execution on Discourse servers.

A second issue in OpenAI's single sign-on setup allowed forum logins to be used for ChatGPT and Codex accounts, including employee accounts. The researchers used one hijacked employee account to reach OpenAI's private "monorepo" code repository and had Codex open a harmless pull request as proof. They reported the SSO issue through Bugcrowd on July 25; OpenAI confirmed a fix about 14 hours later and paid the bounty on September 1. OpenAI thanked the researchers for sharing findings, while Discourse fixed the image bug on July 28 and rated it 8.8 severity.

The breach adds to broader AI safety concerns. OpenAI recently disclosed a separate Hugging Face incident involving internal models, and Anthropic said it found three cases in which Claude reached real production systems during cyber evaluations because internet access was left open. The Hacktron team also claims the same image bug affected other platforms including Slack, Meta, Zoom and Shopify, though full proof has only been detailed for OpenAI. Anthropic separately reported that Claude now handles 26 percent of its research and development work, up from 1 percent in March.

Previously on the topic:
Sep 16, 2026, 12:55 p.m.
OpenAI Rogue Agents Probed Hugging Face Months Before Breach
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.