
OpenAI âÂÂethically hackedâ with help of AnthropicâÂÂs Claude chatbot
US cybersecurity researchers who conducted hack say âÂÂscope of what we could theoretically access was hugeâÂÂ
Cybersecurity researchers have hacked into OpenAI with the help of AnthropicâÂÂs Claude chatbot, in the latest example of security issues at the company.
A team at a US-based startup compromised multiple OpenAI employeesâ ChatGPT accounts, starting a process that enabled them to access their targetâÂÂs software cache â and potentially more.
âÂÂThe scope of what we could theoretically access was huge,â said researchers at Hacktron AI.
Initially, the research team used Claude, which can generate code for hackers, to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform. They then made a harmless âÂÂpull requestâ â an attempt to change the code in a file â to OpenAIâÂÂs service on the GitHub software repository.
Hacktron reported the hack to OpenAI, having carried out the probe under an OpenAI programme that rewarded ethical hackers for testing its systems. The researchers stressed that they had access to, but did not download, the code from the GitHub repository.
Despite initial use of Claude, the researchers said they were largely using OpenAIâÂÂs own cutting edge GPT-5.6 Sol model to carry out the hack.
The Wall Street Journal first reported the latest OpenAI security incident.
An OpenAI spokesperson said âÂÂwe thank the researchers for contacting us and sharing their findingsâÂÂ, adding that the company had addressed the vulnerabilities that had been exploited.
Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack â a common refrain from cybersecurity experts when discussing the impact of AI.
âÂÂWork that once required a well-resourced team and months of effort can now be compressed into days,â said Hacktron, which received a $6,500 payment from OpenAI under the companyâÂÂs bug bounty programme â a scheme under which ethical hackers receive rewards for reporting vulnerabilities.
The hack is the latest safety incident at OpenAI, which revealed in July that a âÂÂswarmâ of agents â the term for AI tools capable of carrying out tasks autonomously â powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test.
This week the San Francisco-based company revealed six more examples of âÂÂunexpected or concerningâ behaviour by its technology, as it warned that the pace of development could not continue at âÂÂmaximum speed for much longerâÂÂ.
OpenAI made the fresh security revelation after AnthropicâÂÂs renewed call at the weekend for a slowdown in AI development, which was supported by the ChatGPT maker as well as Google DeepMind and Elon Musk. Anthropic also repeated warnings that unrestrained AI development posed an existential threat â concerns that some experts are sceptical about.
Donald Trump has rejected calls for a slowdown, citing a need to stay ahead of ChinaâÂÂs AI industry and dismissing âÂÂnegative forces ⦠bringing up things that wonâÂÂt happenâÂÂ.
