A small AI startup used Claude to hack into OpenAI's inner codebase shortly following the OpenAI Hugging Face hack.
Zayne Zhang, the cofounder and CEO of Hacktron, told Business Insider that his investigation squad has begun examining safety vulnerabilities at frontier AI companies akin OpenAI to decide whether they have gaps that could be exploited by AI agents. Hacktron is a San Francisco-based AI cybersecurity startup.
In July, Zhang's squad discovered several gaps in OpenAI's infrastructure. According to Hacktron's disclosure concerning the incident, published on Sunday, any person or OpenAI employee logging into OpenAI's community assistance forum could have had their ChatGPT and Codex accounts hacked.
Hacktron afterward tried to utilize that exposure via Claude. The business had admission to Anthropic's Cyber Verification Program, which relaxed certain cyber restrictions on Claude for authorized safety research, Zhang said.
The squad managed to hack into an OpenAI employee's document and immediate the employee's Codex document to propose changes in OpenAI's inner code repository. Hacktron stated the squad stopped there, didn't admission any inner code, and flagged the matter to OpenAI.
Hacktron stated in its disclosure that the business won a $6,500 bounty from its discovery. The startup was launched small than a twelvemonth ago and has small than 10 employees.
An OpenAI spokesman stated in an emailed declaration to Business Insider concerning Hacktron, "We appreciate the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions."
"The worlds of AI safety and cybersecurity are converging, and we think that having additional cybersecurity experts in the conversation is continually a fine item for the industry," Zhang stated of the incident,
Representatives for Anthropic did not react to a petition for comment from Business Insider.
Hacktron's disclosure comes as AI safety is becoming among the most crucial topics in tech. In latest months, OpenAI, Anthropic, and Meta have disclosed that their agents busy in rogue actions during testing. Fears of an AI apocalypse, driven by unchecked malicious AI agents, have emerged in droves this month.
Read next
Aditi is a news newsman at Business Insider’s Singapore bureau. She covers hustle civilization and the forthcoming of work, focusing on how AI and innovation are reshaping jobs, careers, and workplaces.She earlier worked for The Straits Times, anywhere she wrote breaking news stories for the Singapore desk. She studied communications and endeavor at Nanyang Technological University.