By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Claude Opus 5 Chained Flaws to Access OpenAI Employee Accounts

Three security researchers from the firm Hacktron successfully utilized Anthropic's Claude Opus 5 large language model to chain two distinct software vulnerabilities, ultimately compromising the accounts of several OpenAI employees. This security research, conducted by the Hacktron team, demonstrated a sophisticated attack vector that began with a flaw in the software powering OpenAI's public help forum. The initial exploit allowed the researchers to pivot to a second weakness present within OpenAI's proprietary login system. By chaining these two vulnerabilities, the researchers were able to gain unauthorized access to the ChatGPT and Codex accounts belonging to OpenAI staff members. Following the compromise of these employee accounts, the Hacktron researchers were able to reach an internal OpenAI code repository, indicating a significant breach of internal systems. The research highlights the potential for advanced AI models like Claude Opus 5 to be employed in complex cyberattack scenarios, even when those models are not directly malicious. The attack chain involved a multi-stage process, where the output or capabilities of Claude Opus 5 were instrumental in identifying and exploiting the subsequent vulnerability after the initial entry point was secured. This research underscores the evolving threat landscape where AI tools can be repurposed for offensive security operations, necessitating continuous advancements in defensive measures. The researchers' objective was to demonstrate the feasibility of such chained attacks, emphasizing the need for organizations to rigorously test and secure their internal systems and external-facing services against sophisticated, AI-assisted exploitation techniques. The implications of this research extend to the broader cybersecurity community, prompting a re-evaluation of security protocols and the potential for AI-driven attacks to bypass traditional security defenses. The Hacktron team's findings were presented as a demonstration of security research, aiming to inform and improve the security posture of organizations like OpenAI and others utilizing similar technologies. The specific details of the vulnerabilities exploited were not fully disclosed in the initial report to prevent immediate misuse, but the methodology involved leveraging AI to navigate and exploit interconnected security weaknesses. The successful breach into an internal code repository signifies a critical security event, as such repositories often contain sensitive intellectual property and proprietary code that, if exposed, could lead to further exploitation or competitive disadvantage.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.