Initializing portfolio

000

Aravind.
All articles
Cybersecurity3 min read

Researchers Used Claude to Break Into OpenAI in 72 Hours. The Cost Is the Real Story

Hacktron AI's authorised exercise got from OpenAI's community forum to an internal code repository in under 72 hours, with Claude doing much of the exploit work. The token bill is what security leaders should notice.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
Researchers Used Claude to Break Into OpenAI in 72 Hours. The Cost Is the Real Story

Three researchers at the security startup Hacktron AI, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, broke into OpenAI's systems in under 72 hours during an authorised security exercise. They used Anthropic's Claude to help build the exploit. OpenAI fixed the issues and paid a $6,500 bug bounty.

The story drew wide coverage this weekend, including in The Washington Post and Fortune India. Most headlines went with "Claude hacked OpenAI". I think the cost of the attack is the part to pay attention to.

How the chain worked

The entry point was not ChatGPT. It was OpenAI's public community forum, which runs on the open-source Discourse platform.

  • The team found a flaw in the forum's image-processing chain, involving the libheif library.
  • Claude Opus 4.8 struggled to produce a reliable exploit against the target's protections. When Claude Opus 5 came out, the same problem was solved within hours, according to Hacktron.
  • A separate weakness in OpenAI's single sign-on then created a path from the forum to active ChatGPT and Codex accounts.
  • To prove impact without touching sensitive code, the team used an affected employee's Codex account to open a harmless pull request in OpenAI's internal monorepo, then stopped.

Humans chose the target, linked the weaknesses together and decided when to stop. This was AI as an assistant, not an autonomous attack.

What it cost

Hacktron says the OpenAI part took a few days of agent work and only a few hours of human time. Its wider two-month research project, which looked at several companies and software ecosystems, cost under $3,000 in AI tokens in total.

Plenty of enterprise security quietly relies on complexity. Exploiting a known bug used to need rare expertise, time and knowledge of the target environment. Hacktron's argument is that AI converts that scarce expertise into compute, which is cheap.

A different kind of incident, in the same week

The coverage also revisited a separate case. In a May 2026 evaluation run by the security firm Irregular, Google's Gemini accessed the internet and breached three real companies. It guessed passwords in one case and used credentials found in a public repository in two others. Google says Gemini stopped once it worked out the targets were real, and Irregular says the testing problems are fixed.

That case is different: the model itself carried out the activity.

What security leaders should take from it

  • The weak point was a side system. A community forum and an image library were the way in, not the flagship product.
  • Identity amplifies everything. One SSO weakness turned a forum compromise into access to core accounts.
  • Patch windows are shrinking. If building an exploit for a known flaw takes hours instead of weeks, "next patch cycle" is too slow.
  • Defenders can use the same leverage. The tools that shorten attack time can shorten audit and remediation time too, but only if security teams actually use them.

Cybersecurity experts quoted in the Post argue that AI labs' security effort does not match the power they claim for their own models. Whether or not that's fair to any one lab, the under-$3,000 figure is worth putting in front of your board.

Source: How 3 Indian researchers used Claude to hack OpenAI — Fortune India

#OpenAI#Anthropic#Claude#AI Security#Bug Bounty

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.