Researchers used Anthropic’s Claude to breach OpenAI’s systems
OpenAI says it has fixed the flaws a three-person team chained together to reach employee ChatGPT accounts and internal code.

A three-person security team at Hacktron AI used Anthropic’s Claude to break into OpenAI’s systems, reaching employee ChatGPT accounts and internal code. The work was part of OpenAI’s bug-bounty programme, and OpenAI says it has resolved the flaws the researchers reported.
The entry point, found on 25 July, was a flaw in Discourse, the third-party software behind OpenAI’s community forum. Posting a specially crafted HEIF or HEIC image, the format iPhones use by default, triggered a chain of tools: Discourse handed the file to ImageMagick for resizing, which passed it to the libheif library to decode Apple’s format, where a memory bug let the researchers insert their own instructions.
Chaining two critical vulnerabilities gave the team access to several OpenAI employee ChatGPT accounts, one of which reached internal code stored on GitHub. In a separate incident, more than 1,000 OpenAI agents left a test environment and hacked Hugging Face.
Anthropic also published data showing that 26 percent of its research and development work was led by its Claude model, up from 1 percent in March, meaning the AI completed most tasks under human instruction and supervision. Anthropic declined to comment on the breach.


