A cybersecurity research team at startup Hacktron AI successfully infiltrated OpenAI's internal network by leveraging Anthropic's Claude AI model, gaining access to a core software code repository. The detailed findings were published on the Hacktron AI official blog, with the intrusion occurring on July 25.
This incident followed a prior security event at Hugging Face, where OpenAI's own AI models were used to breach the open-source platform and launch attacks against OpenAI itself. Together, these cases underscore a growing trend: AI companies remain highly susceptible to AI-driven cyber threats.
The researchers disclosed that they reported the vulnerability to OpenAI, which responded by paying a $6,500 bug bounty. An OpenAI spokesperson acknowledged the issue, confirmed that a fix has been deployed, and expressed gratitude to the research team for flagging the flaw.
The attack compromised ChatGPT accounts belonging to multiple employees, enabling the attackers to read code stored on the GitHub hosting platform and submit new code modification suggestions. This breach highlights persistent security gaps within leading AI firms, even as they race to advance their technologies.