By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Researchers Hack OpenAI Using Anthropic Tool

Cyber researchers successfully breached OpenAI's systems by exploiting a vulnerability in a ChatGPT account belonging to an OpenAI employee. This security incident, which allowed the researchers to view private software information and propose modifications, underscores the ongoing security challenges faced by leading artificial intelligence companies amidst increasing regulatory and public scrutiny. The researchers gained access to the OpenAI employee's account through an Anthropic tool specifically developed for cybersecurity professionals. This exploit was part of a paid program designed to proactively identify and address security flaws before they could be leveraged by malicious actors. The incident highlights the complex and interconnected nature of the AI industry, where tools developed by one company can inadvertently reveal weaknesses in another, even a direct competitor.
Anthropic, the developer of the tool used in the breach, is a prominent AI safety and research company known for its large language models, including the Claude series. OpenAI, the target of the breach, is a leading AI research laboratory responsible for developing models like GPT-3.5 and GPT-4, which power the widely used ChatGPT. The use of Anthropic's security tool by external researchers to probe OpenAI's defenses demonstrates a dual-use nature of advanced AI technologies, where tools designed for protection can also be repurposed for offensive security testing. This event occurs at a time when AI companies are under intense pressure to enhance their safety protocols and demonstrate robust security measures to governments and the public.
The specific details of the vulnerability exploited remain undisclosed, but the incident involved gaining access to an employee's ChatGPT account. This access provided the researchers with the ability to read sensitive internal software information. Furthermore, they were able to suggest changes to the software, indicating a level of access that could potentially impact the integrity of OpenAI's development processes. The researchers were compensated for their work as part of a bug bounty or vulnerability disclosure program, a common practice in the cybersecurity industry aimed at incentivizing the ethical reporting of security flaws. This program, facilitated by Anthropic's specialized tool, allowed the researchers to operate within a controlled environment, ensuring their activities were for security testing purposes.
The breach raises significant questions about the security posture of major AI developers and the potential for sophisticated attacks targeting their proprietary information and systems. As AI models become more powerful and integrated into critical infrastructure, the security of the underlying AI companies and their intellectual property becomes paramount. The incident serves as a stark reminder that even organizations at the forefront of AI development are not immune to cyber threats. The collaborative yet competitive landscape of AI research means that vulnerabilities discovered in one company's ecosystem could have broader implications for the entire sector, necessitating continuous vigilance and robust security practices across the board.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.