Three people plus Claude broke into the OpenAI core codebase! AI is lowering the barrier to hacking.
Artificial intelligence tools are reshaping the threshold and boundaries of cyberattacks. A three-person independent security research team successfully compromised OpenAI employee accounts and gained access to the company's core codebase using Anthropic's Claude software.
According to a report by The Wall Street Journal on the 17th, three researchers from security research firm Hacktron AI, through OpenAI's bug bounty program, used AI-assisted methods to breach OpenAI's defenses in July of this year, successfully gaining access to the company's private codebase called "Monorepo". OpenAI paid the team a bounty of $6,500 and confirmed that all the vulnerabilities have been fixed.
This incident comes just two weeks after another AI security breach—when a group of AI agents escaped from OpenAI and subsequently attacked the AI platform Hugging Face. These two consecutive incidents prompted OpenAI to reassign a quarter of its production engineers to defensive roles and this week publicly disclosed previously undisclosed security incidents and a new information disclosure policy.
Greg Brockman, co-founder and president of OpenAI, said the company found "several serious issues" during the security audit and has fixed them.
Vulnerability chain: From forum image processing to core code library
The attack began on July 23 when Hacktron AI researchers discovered a vulnerability related to image file processing in Discourse, a hosting service for the OpenAI community discussion forum. The researchers used a special version of Claude Opus 4.8, intended for qualified cybersecurity practitioners, and asked them to write attack code that exploited the vulnerability, but the initial attempt was unsuccessful.
That evening, Anthropic released Opus 5, and the following day Claude found a viable exploit path. The generated attack code allowed researchers to gain access to the Discourse server hosting the OpenAI discussion forum and obtain users' authentication tokens—unique strings of letters and numbers that serve as credentials for accessing online services.
To the researchers' surprise, these tokens also worked on ChatGPT, and some of them belonged to OpenAI employees. These tokens could also be used to access OpenAI's GitHub service—its software code repository. Discourse stated that the vulnerability was patched on July 25th (the day they received the notification). OpenAI stated that its review of GitHub showed that there was only "limited read" access to metadata and code changes in the private code repository.
"Monorepo": OpenAI's secret algorithm weapon
According to media reports citing sources familiar with the matter, the "Monorepo" library accessed by researchers is a large software codebase from OpenAI, storing the company's core algorithmic secrets and key to improving model speed and efficiency. However, the sources pointed out that the library does not contain model weights—OpenAI's true core asset, consisting of trillions of parameters in large language models that determine how the model filters and processes information.
Researchers used ChatGPT as an interface to read files in Monorepo, but stopped after realizing they might have accessed sensitive data. Previously, they had sent a "pull request" via chatbot, suggesting adding the phrase "Hacktron AI Team PoC" and links to related personnel's social media accounts to a document as proof of successful access. This request was not accepted.
"We don't believe our capabilities are comparable to those of other threat actors," said Mohan Pedhapati, CTO of Hacktron AI. "We're just three ordinary people with Claude and Codex subscription accounts."
AI tools lower the barrier to attack, leading to a sharp increase in security threats.
This incident reflects broader cybersecurity concerns. Joshua Saxe, CTO of AI security company Abundant Security, after reviewing Hacktron AI's incident report, stated that software systems worldwide are riddled with vulnerabilities, which have gone undiscovered in the past because, until last year, there were only a few thousand experts capable of identifying them. "Now, AI agents are disseminating this capability to people with lower levels of technical skills," he said.
Data from cybersecurity firm ThreatDown further corroborates this trend: on online forums, criminals can purchase AI-enhanced account access similar to that used by Hacktron researchers for as little as $800.
Amidst the escalating competition in AI, researchers involved in the attack warned that this case demonstrates the high likelihood that sophisticated cyberattack teams could steal core AI secrets in similar ways. OpenAI CEO Sam Altman and other tech executives signed a petition last Saturday calling for a halt to AI development, arguing that the current pace is exceeding the security control capabilities of individual companies.
Risk warning and disclaimerInvesting involves risk; please exercise caution. This article does not constitute personal investment advice and does not take into account the specific investment objectives, financial situation, or needs of individual users. Users should consider whether any opinions, views, or conclusions in this article are suitable for their specific circumstances. Any investment decisions made based on this information are at your own risk.