Researchers used Anthropic's Claude to breach OpenAI's internal code repo in 72 hours
Security researchers at Hacktron AI, led by founder s1r1us (Mohan Pedhapati), used Anthropic's Claude models to hack into OpenAI's systems, taking over employee accounts and accessing the internal 'Monorepo' GitHub repository within 72 hours, as reported by the Wall Street Journal. The attack chain started with a single HEIC image upload to OpenAI's community forum, exploiting a heap buffer overflow in libheif. The researchers reported the flaws to OpenAI and did not access internal code themselves, but sent a pull request from an employee's Codex account to prove access.
Coverage timeline
机器之心机器之心
天道好轮回,苍天饶过谁?入侵过 Hugging Face 和 Ruby 生态 的 OpenAI 原来也被入侵过!并且,入侵者使用的还是其主要竞对 Anthropic 的模型。 就在几个小时前,Electrovolt Security 与 Hacktron AI 创始人 s1r1us 在 𝕏 上发布了一系列推文,分享了其团队在 7 月份借助 Claude 成功入侵 OpenAI 的故事,引发广泛关注。 https://x.com/S1r1u5_/status/2100777801335095383 严格来说,这个故事并不算新。完整的技术复盘早在 9 月 13 日就挂在了 Hacktron 的博客上,并且标题颇有些挑衅意味:「 Hacking OpenAI 」。 博客地址:https://www.hacktron.ai/blog/hacking-openai 真正让它在今天引爆的,是《华尔街日报》的独家报道《 黑客用 Anthropic 的 Claude 攻破 OpenAI 》,以及 s1r1us 本人下场把整条攻击链摊开讲了一遍。推文发布数小时内浏览量已超过 55 万,Hacker News 上也热度极高。 s1r1us 本名 Mohan Pedhapati,是 Hacktron AI 的联合创始人兼 CTO。参与这次研究的还有安全研究主管 Harsh Jaiswal 和研究员 Rahul Maini, 一共 3 个人 。 时间上, 从初始发现到拿到 OpenAI 内部代码仓库的访问权限,全程不到 72 小时 。 Hacktron 博客给出的九步攻击链示意图 72 小时:从一张图片到 OpenAI 的内部单体仓库 整条链路的起点就只是「 上传一张 HEIC 格式的图片 」。 OpenAI 的用户社区 community.openai.com 跑在 Discourse 上。Discourse 平时用 FastImage 做图片校验,但 FastImage 不支持 HEIF,于是这类文件被转交给 ImageMagick 的 magick 命令去转换,底层的 libheif 解析器就这样直接暴露在了攻击者可控的文件面前。 Hacktron 团队在 7 月 23 日开始审计这条图片上传流水线,随后在 libheif 中确认了 一个堆缓冲区溢出 。 最值得安全从业者警觉的是这

TechCrunch AIAditya Mehta, Rebecca Bellan
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.
The Verge AIStevie Bonifield
A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic's Claude Opus 4.8 and 5, the Wall Street Journal reports. They were able to access OpenAI's GitHub repository, called "Monorepo," which reportedly contains "OpenAI's algorithmic secrets," according to the Wall Street Journal 's sources. They stopped short of accessing internal code in Monorepo themselves, but sent a pull request from an employee's Codex account to prove they gained access. They were able to get in through Discourse, the third-party service that hosts OpenAI's community f … Read the full story at The Verge.
