White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours — and it is a case study in just how fast AI is advancing
The researchers struggled to abuse the exploit with an AI agent on Opus 4.8, but the release of Opus 5 changed everything.
Security researchers employed Claude Opus 5 to infiltrate an OpenAI employee's ChatGPT account, exploiting a flaw in OpenAI community forums' image processing. The entire process, from vulnerability discovery to repository access, took less than 72 hours within an OpenAI bug bounty program. Utilizing a "special version" of Anthropic's Claude, the hackers initially failed with Claude Opus 4.8 but successfully created a local remote code execution (RCE) using Claude Opus 5.
The researchers noted that new AI models are increasingly capable, as the exploit was created within a few hours of Opus 5's release, while it took hours of human interaction to achieve the same result with Opus 4.8. The full timeline from initial discovery to OpenAI repo access took 72 hours, with the libheif exploit research taking two months for three researchers, costing under $3,000 in tokens.
The AI agent set a local remote code execution (RCE) loop, adapting the exploit for each company within one or two days. While OpenAI acknowledged the vulnerability and patched it, the researchers warned about the dangers of relying solely on AI agents for cybersecurity, emphasizing the importance of human oversight and accountability.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 7 other outlets
- The 'Godfather of AI' backs a new watchdog plan to track OpenAI and Anthropic's AI risks from the inside businessinsider.com
- OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot theguardian.com
- Protesters target OpenAI and Anthropic in San Francisco over AI safety fears euronews.com
- Anthropic and OpenAI need truly independent safety evaluators, experts say in public letter cnbc.com
- Security researchers used Anthropic's Claude to hack into OpenAI in under 72 hours qz.com
- Los investigadores logran vulnerar OpenAI utilizando modelos de Anthropic expansion.com
- Chinese AI models fetch fraction of OpenAI, Anthropic revenue despite lower costs: report seekingalpha.com