Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
연구자들이 Claude Opus 5를 이용해 OpenAI 직원 계정을 takeover에 성공했다.
Hacktron의 세 연구자는 Anthropic의 Claude Opus 5를 활용하여 두 가지 취약점을 연결해 OpenAI 직원의 ChatGPT 및 Codex 계정을 탈취한 뒤, 내부 코드 저장소에 접근했다. 이 과정은 OpenAI의 공개 도움말 포럼을 운영하는 소프트웨어의 버그에서 시작해 OpenAI의 로그인 시스템의 약점으로 이어졌다. 이는 보안 연구의 일환으로 진행됐다.
Researchers used Claude Opus 5 to take over OpenAI employee accounts.
Three researchers from the security firm Hacktron used Anthropic's Claude Opus 5 to exploit two vulnerabilities to take over the ChatGPT and Codex accounts of several OpenAI employees, gaining access to an internal OpenAI code repository. The chain began with a bug in the software running OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was part of their security research.