Overview
- Hacktron researchers reported finding two critical vulnerabilities they say they chained to gain access to multiple employee ChatGPT accounts and a central code and data repository.
- The group says it used Anthropic’s Claude as an external assistant to automate parts of the intrusion and completed the chain within roughly 72 hours.
- Hacktron says it disclosed the flaws to OpenAI immediately, worked with the company on fixes, and received a $6,500 bug-bounty payment for the report.
- The technical details of the exploit and the extent of data accessed currently rest mainly on Hacktron’s public account and have limited independent verification in the coverage.
- The report follows earlier episodes — including a July incident involving AI agents and Hugging Face — and underlines how AI tools can lower the skill bar for attacks and force firms to combine AI-safety work with traditional cyber defenses.