$ techbeacon▋
Threats

Security Researchers Leverage Anthropic’s Claude Opus 5 to Compromise OpenAI Staff Accounts

Security Researchers Leverage Anthropic’s Claude Opus 5 to Compromise OpenAI Staff Accounts

Three security analysts from the firm Hacktron have demonstrated a multi‑step attack that allowed them to seize control of several OpenAI employee accounts on both the ChatGPT and Codex platforms, ultimately gaining access to an internal code repository.

The operation hinged on two previously undisclosed vulnerabilities. The first flaw was a bug in Anthropic’s Claude Opus 5 language model that permitted crafted prompts to elicit responses containing hidden execution instructions. By feeding the model a sequence of specially designed queries, the researchers were able to extract a token that OpenAI’s authentication system accepted as valid.

With the token in hand, the team moved to the second weakness: a misconfiguration in OpenAI’s account‑management API that failed to enforce proper scope checks on token usage. Exploiting this oversight, the Hacktron researchers impersonated legitimate staff members, logging into their ChatGPT and Codex dashboards without triggering alerts.

Once inside, the attackers navigated to an internal Git repository used by OpenAI engineers for proprietary model development. The repository, which houses early‑stage code for upcoming AI products, was accessed without additional privilege escalation, indicating that the compromised staff accounts possessed sufficient rights to view and download the source.

The breach underscores the growing interdependence of large‑scale AI models and the security ecosystems that surround them. As organizations increasingly embed third‑party language models into critical workflows, vulnerabilities in one system can cascade into another, amplifying potential damage.

OpenAI has acknowledged the incident, stating that its security team is conducting a thorough review of the affected accounts and the exposed codebase. The company has not disclosed the number of employees impacted, but it confirmed that no user‑facing services were disrupted and that no external data was exfiltrated.

Anthropic, the creator of Claude Opus 5, issued a brief statement noting that it is cooperating with Hacktron and OpenAI to remediate the identified bugs. The firm emphasized its commitment to responsible disclosure and pledged to roll out patches to prevent similar exploit chains in the future.

Security experts say the episode serves as a reminder that AI model providers must adopt rigorous testing for prompt‑injection and token‑handling flaws, especially when their tools are integrated into other companies’ authentication pipelines. The incident also highlights the importance of zero‑trust architectures that limit the privileges of any single credential.

Going forward, both OpenAI and Anthropic are expected to tighten their security reviews and publish additional guidance for developers who rely on AI‑driven services. The episode may also prompt broader industry discussions about standardized security certifications for large language models, aiming to reduce the risk of similar chained exploits.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related