Open AI Paid Anthropic a Bug Bounty!!

Open AI Paid Anthropic a Bug Bounty!!

Security researchers from Hacktron used Anthropic's Claude Opus 5 to exploit two linked vulnerabilities that gave them control of OpenAI employee accounts and access to an internal code repository. The attack began with an image-processing flaw in the Discourse forum software that OpenAI used for its public support site, then leveraged a weakness in OpenAI's authentication system to hijack ChatGPT and Codex accounts belonging to several employees. This was responsible security testing rather than a malicious attack. The researchers reported their findings to OpenAI, demonstrated access by creating a harmless pull request in the internal repository, and stopped there. OpenAI confirmed a fix within roughly fourteen hours and paid a six thousand five hundred dollar bounty.

The initial vulnerability involved how Discourse processed HEIC and HEIF image files through the libheif library. A flaw in that library allowed a specially crafted image to corrupt server memory, which the researchers used to bypass standard protections and execute code on the forum server. Once they controlled the forum, they exploited OpenAI's shared single sign-on system to take over employee accounts without requiring any user interaction. The authentication weakness was specific to OpenAI's implementation rather than a problem with Discourse itself, but it meant that any service using that same login system could potentially provide similar access to internal tools.

The role of artificial intelligence in this attack is particularly significant. The researchers initially struggled with Claude Opus 4.8 to create a working exploit, but when Anthropic released Claude Opus 5 on July 24, the new model generated functional exploit code within hours. They bypassed the model's built-in protections by framing their work as a capture-the-flag training exercise and emphasized that human expertise remained essential throughout the process. This incident was part of a broader project called HEIF Heist, where Hacktron reportedly found similar vulnerabilities in software used by major companies including Slack, Meta, GitHub Enterprise, and various web frameworks, spending less than three thousand dollars on AI usage overall.

The broader implications are clear for both defenders and attackers. Any service processing HEIC, HEIF, or AVIF image files with outdated versions of libheif could be vulnerable, and organizations using shared single sign-on between public and internal systems create significant risk if any connected service is compromised. More fundamentally, advanced AI models are dramatically reducing the time and expertise required for sophisticated offensive security work. There is no evidence this particular vulnerability was exploited maliciously, but the demonstration shows how AI is actively changing the threat landscape for both legitimate security research and real attacks.

Stay secure — stay Wavasec. 🔐