White-hat hackers breach OpenAI using Anthropic's Claude Opus 5
White-hat researchers used Anthropic’s Claude Opus 5 to exploit an image-processing flaw, compromising an OpenAI employee’s account and internal GitHub. This incident demonstrates how AI agents lower…
A small group of white‑hat security researchers used Anthropic’s Claude Opus 5 to turn an image‑processing flaw into an exploit chain that compromised an OpenAI employee’s ChatGPT account and reached the company’s internal GitHub environment, according to a report by VentureBeat on March 12 2024. The researchers were able to map the vulnerability into a full attack in minutes, and the breach was contained before any external data was exfiltrated.
The incident shows how AI coding agents are changing the economics of sophisticated hacking. Claude Opus 5 can generate code, debug, and automate complex tasks. This lets even small teams create and test exploits faster than before. OpenAI had never before faced a breach that used an AI agent to chain an image‑processing vulnerability into an internal compromise.
The flaw was in a third‑party image‑processing library. The researchers injected malicious code that, with the help of the AI, escalated privileges and accessed internal repositories. OpenAI confirmed the account compromise and said the breach was limited to the employee’s account and the internal GitHub environment. The researchers reported the issue to OpenAI’s security team and provided full evidence, following responsible disclosure practices.
OpenAI is reviewing its security controls and updating its image‑processing pipeline. The
Read Full Story at VentureBeat →


