Key Takeaways
According to CryptoSlate, researchers used Anthropic's Claude to chain two vulnerabilities and breach OpenAI accounts and an internal code repository.

According to CryptoSlate, three security researchers from cybersecurity startup Hacktron utilized Anthropic’s Claude to breach OpenAI accounts and reach an internal code repository within 72 hours. In July, the researchers chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure to access multiple employees' ChatGPT and Codex accounts. A compromised Codex account connected to OpenAI’s GitHub organization granted access to the internal software environment.
Reporting by CryptoSlate noted that the attack accelerated after Anthropic released Claude Opus 5. The model overcame an exploitation hurdle involving ImageMagick and the libheif decoding library on OpenAI’s Discourse forum. After gaining administrative access to the forum, a separate single-sign-on weakness allowed the team to move into employee accounts.
OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receiving the report and paid a $6,500 bounty. Hacktron co-founder Mohan “s1r1us” Pedhapati stated that the episode demonstrated how AI reduces the specialized labor required to develop exploits, compressing timelines from months to days. However, the startup emphasized that skilled human guidance remained essential throughout the operation.
Source & Fact-Check Note
This report is synthesized from coverage by CryptoSlate. Information has been fact-checked and structured for market clarity by CoinQuickly’s research desk.
Read original article at CryptoSlate ↗

