AI vs. AI: Claude Opus 5 Breaches OpenAI's Codebase in Under 72 Hours

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
In a striking demonstration of advanced AI's dual-use capabilities, a small team of white hat security researchers from Hacktron AI successfully breached OpenAI internal systems, including access to their core 'Monorepo' private codebase. The audacious exploit, executed in under 72 hours, leveraged OpenAI rival Anthropic latest AI model, Claude Opus 5, to craft sophisticated attack code. This incident, part of an authorized bug bounty program, has sent ripples through the AI community, highlighting critical vulnerabilities in even the most cutting-edge AI organizations. The researchers chained two distinct security flaws: first, an image-processing vulnerability (a heap buffer overflow in the libheif library) on OpenAI community forum, which runs on Discourse, allowed them to achieve remote code execution. Crucially, an earlier Anthropic model, Claude Opus 4.8, struggled with this task, but the more powerful Claude Opus 5 generated a working exploit within hours, showcasing the rapid advancements in AI capabilities for offensive cybersecurity. The second flaw exploited a weakness in OpenAI single sign-on (SSO) system, enabling the team to pivot from compromised forum access to an OpenAI employee's ChatGPT account and subsequently, their internal GitHub repositories. OpenAI has since patched the issues and paid a $6,500 bounty for the disclosure. This high-profile breach underscores the escalating stakes in AI security, prompting OpenAI President Greg Brockman to reallocate 25% of production engineers to security efforts. As AI models grow more capable, they become potent tools for both defense and offense, blurring ethical lines and challenging existing cybersecurity paradigms. The incident serves as a stark reminder for AI labs and companies to prioritize robust security measures, including comprehensive AI red teaming, and to continuously adapt their defenses against increasingly sophisticated, AI-powered threats. The industry must now grapple with how to ensure AI models are not misused to compromise the very systems they are designed to protect, fostering a new era of 'AI vs. AI' cybersecurity.