RUECAT DEX
All news
CryptoSlate 2h ago

Anthropic AI Assisted Researchers in Compromising OpenAI Infrastructure

Cybersecurity researchers utilized Anthropic's Claude to penetrate OpenAI internal systems and access code repositories within 72 hours.

Abstract digital vault scene representing the OpenAI security breach with neon accents.

A critical vulnerability assessment has demonstrated how modern artificial intelligence tools can rapidly accelerate cybersecurity intrusions, culminating in an OpenAI security breach during a recent authorized test. Security specialists from the startup Hacktron managed to bypass internal security perimeters and access sensitive developer infrastructure in under three days. The incident highlights the growing potential of frontier models to identify complex exploit chains across sophisticated enterprise environments.

The intrusion was executed by combining an image-processing flaw with underlying weaknesses in user identity management, according to CryptoSlate. By chaining these distinct attack vectors, the research team successfully compromised multiple staff accounts across ChatGPT and Codex services. Most notably, one of the hijacked Codex accounts held direct administrative connectivity to OpenAI's internal GitHub environment, allowing researchers to inspect proprietary source code repositories within the 72-hour exercise.

This demonstration illustrates how defensive barriers are being tested by automated reasoning agents that can piece together multi-step exploits far faster than traditional manual workflows. The researchers leveraged Claude to systematically probe architecture gaps, formulate payloads, and automate lateral movement across the target environment. The findings shed light on the dual-use reality of autonomous software, where defensive testing and malicious penetration utilize nearly identical underlying models.

Industry experts warn that organizations operating complex identity management architectures must re-evaluate their access models against AI-assisted threats. With code repositories and development environments representing primary targets for state-sponsored and independent actors, basic perimeter controls may no longer suffice. Observers are now tracking how major artificial intelligence labs update their internal isolation boundaries and enforce hardware-level authorization to prevent similar lateral breaches.

Key takeaways

  • Hacktron researchers bypassed OpenAI access controls in under 72 hours using Anthropic's Claude model.
  • The attack chained an image-processing bug with identity flaws to penetrate internal GitHub codebases.
  • The incident highlights the accelerating capabilities of AI models in finding enterprise software vulnerabilities.

Related tags