NewsLayer.com
NewsLayer PulseLIVEBTC$86,175-0.48%ETH$2,753-0.84%SOL$118.48-0.33%XRP$1.58+2.62%DOGE$0.1005+0.62%ADA$0.2564+4.48%Total Cap$3.08T+0.23%Layer Index58 Neutral

Researchers used Claude to hack OpenAI

We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself.

Malwarebytes

Publisher

Sep 22, 2026 at 10:24 AM UTC · 4 Min. Lesezeit

Researchers used Claude to hack OpenAI
Image via Malwarebytes
Übersetzung…

We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself.

The hack, which also exposed a bug affecting dozens of other major online services, was conducted as security research. OpenAI paid the researchers for reporting a flaw in its systems through its bug bounty program.

Researchers at cybersecurity tools vendor Hacktron wrote up their adventures in mid-September. A few months earlier, they had begun looking for security flaws at companies developing frontier AI models, which are highly capable models such as those powering ChatGPT and Claude.

Using Anthropic’s Claude, the researchers went from investigating an image-processing flaw to accessing an internal OpenAI software repository in less than 72 hours. They deliberately avoided viewing sensitive information.

To get inside OpenAI, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini found two vulnerabilities and chained them together. The first wasn’t specific to OpenAI. It involved a bug in an image-upload feature in the Discourse community forum software.

This feature processes images uploaded by users and relies on a low-level software library called libheif. Uploading a specially crafted image could trigger a flaw in the library, allowing an attacker to gain control of the Discourse server.