signalTechCrunch AI2026-09-19
Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to chain two critical vulnerabilities - a memory bug in the libheif image library (accessed via OpenAI's Discourse forum) and a flaw enabling account takeover - to breach OpenAI employee ChatGPT and Codex accounts, earning a $6,500 bug-bounty award. Opus 4.8 failed to produce a working exploit, but Opus 5 succeeded within hours; the libheif bug had been patched months earlier but never assigned a CVE, leaving Discourse running the vulnerable version. OpenAI has since resolved the issues.
- why now
- New Opus 5 enabled OpenAI hack
- evidence
- 3 sources carry this story · confidence medium
- topic
- AI Industry Impact
- source
- TechCrunch AI
#Claude#OpenAI
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source