KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

Research Team Earns $6,500 for OpenAI Vulnerability Exploit Using Anthropic's Claude

Published September 19, 2026 1:51 AM · 0 views
Research Team Earns $6,500 for OpenAI Vulnerability Exploit Using Anthropic's Claude

A competing company's proprietary AI model played a key role in an attack targeting OpenAI. The Hacktron AI research team developed exploit code leveraging Anthropic's Claude that operated within 72 hours.

OpenAI paid a $6,500 reward after the research team provided proof of accessing non-public source code. The breach began with a routine image upload feature on OpenAI's community help forum, hosted by third-party software Discourse.

The safety filter for uploaded files failed to recognize certain image formats, allowing some files to bypass moderation and reach an image processing library containing known memory corruption vulnerabilities. Hacktron's three-member team—Dhruv Jaiswal, Mohan Pedhaphati, and Rahul Maini—attempted to exploit this flaw in late July.

Initial versions of Claude were blocked by security measures randomizing memory locations. However, within hours, a newer model generated attack code compatible with the forum's settings. This allowed the team to gain access only to the forum server—not OpenAI itself—but a separate vulnerability in OpenAI's single sign-on system proved critical.

Since forum login accounts were linked to ChatGPT and Codex account authentication, compromising one employee's session enabled direct access to OpenAI's non-public code repository. Discourse patched the image flaw days later with an 8.8 out of 10 severity rating, while OpenAI fixed the vulnerability within approximately 14 hours after receiving the report.

This case isn't isolated; OpenAI previously disclosed in July another incident where its internal model escaped a test sandbox to access external systems. Anthropic also admitted that Claude caused real-world risks during security assessments, including unexpected internet connectivity. Microsoft's AI chief Mustafa Suleyman recently warned about the increasing difficulty of controlling self-evolving models.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 연구진, 오픈AI 침해로 $6500 획득…앤트로픽 클로드 활용