Security researchers used Claude to help them hack into OpenAI

Security researchers used Claude to help them hack into OpenAI

安全研究人员利用 Claude 协助入侵 OpenAI

A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic’s Claude Opus 4.8 and 5, The Wall Street Journal reports. They were able to access OpenAI’s GitHub repository, called “Monorepo,” which reportedly contains “OpenAI’s algorithmic secrets,” according to The Wall Street Journal’s sources.

据《华尔街日报》报道,Hacktron 的三名独立安全研究人员表示,他们利用 Anthropic 的 Claude Opus 4.8 和 5 版本,在不到 72 小时内就成功入侵了 OpenAI 的员工账户。据《华尔街日报》的消息来源称,他们成功访问了 OpenAI 名为“Monorepo”的 GitHub 存储库,据称其中包含了“OpenAI 的算法机密”。

They stopped short of accessing internal code in Monorepo themselves, but sent a pull request from an employee’s Codex account to prove they gained access. They were able to get in through Discourse, the third-party service that hosts OpenAI’s community forums, by exploiting an issue with the system it uses to process HEIF images. According to Hacktron, Claude Opus 5 launched in the evening on July 24th, and by 10AM the next day they had used it to achieve RCE on Discourse Cloud and accessed OpenAI’s instance.

他们并未进一步获取 Monorepo 中的内部代码,而是通过一名员工的 Codex 账户发送了一个拉取请求(pull request)以证明其已获得访问权限。他们通过利用 Discourse(托管 OpenAI 社区论坛的第三方服务)在处理 HEIF 图像系统中的漏洞,成功进入了该系统。据 Hacktron 称,Claude Opus 5 于 7 月 24 日晚间发布,到第二天上午 10 点,他们就已经利用该模型在 Discourse Cloud 上实现了远程代码执行(RCE),并访问了 OpenAI 的实例。

Their HEIF Heist project took “only one or two days” to adapt to different companies, including OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and others, using less than $3,000 in tokens, and to their knowledge, was only detected by one target, Shopify. The vulnerabilities Hacktron reported to Discourse and OpenAI have since been fixed, and Hacktron says OpenAI paid it $6,500 for finding the bug, but as Hacktron CTO Mohan Pedhapati said to the WSJ, “I don’t think we are as strong as Chinese threat actors… We’re just three guys with Claude and Codex subscriptions.”

他们的“HEIF 劫持”(HEIF Heist)项目仅用了“一两天”时间就适配到了包括 OpenAI、Slack、Meta、GitHub 企业版、Rails、Next.js、ImageMagick 等在内的多家公司,且消耗的 Token 费用不到 3,000 美元。据他们所知,该攻击仅被其中一个目标 Shopify 检测到。Hacktron 向 Discourse 和 OpenAI 报告的漏洞现已修复,Hacktron 表示 OpenAI 为此支付了 6,500 美元的漏洞赏金。但正如 Hacktron 首席技术官 Mohan Pedhapati 对《华尔街日报》所言:“我不认为我们有中国威胁行为者那么强大……我们只是三个拥有 Claude 和 Codex 订阅的普通人。”