A squad of three autonomous safety researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, the Wall Street Journal reports. They were capable to admission OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to the Wall Street Journal’s sources.
They stopped abbreviated of accessing inner code in Monorepo themselves, but sent a drag petition from an employee’s Codex document to demonstrate they gained access. They were capable to get in through Discourse, the third-party assistance that hosts OpenAI’s community forums, by exploiting an matter alongside the scheme it uses to procedure HEIF images. According to Hacktron, Claude Opus 5 launched in the evening on July 24th, and by 10AM the next day they had used it to accomplish RCE on Discourse Cloud and accessed OpenAI’s instance.
Their HEIF Heist project took “only one or two days” to modify to distinct companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick and others, using small than $3,000 in tokens, and to their knowledge, was lone detected by one target, Shopify. The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron says OpenAI paid it $6,500 for finding the bug, but as Hacktron CTO Mohan Pedhapati stated to the WSJ, “I don’t think we are as powerful as Chinese danger actors… We’re fair three guys alongside Claude and Codex subscriptions.”
Follow topics and authors from this narrative to see additional akin this in your personalized homepage nourish and to obtain email updates.