Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

White-Hat Researchers Breach OpenAI Using Claude, Raising Questions About AI-Assisted Hacking

A team affiliated with security startup Hacktron AI chained three vulnerabilities to access OpenAI's private code repository in under 72 hours, collecting a $6,500 bounty. The exploit development work was aided by Anthropic's Claude Opus 5, highlighting growing concerns about AI-accelerated attack capabilities in the cryptocurrency sector.
1 hour ago 9 views
White-Hat Researchers Breach OpenAI Using Claude, Raising Questions About AI-Assisted Hacking

Researchers from Hacktron AI successfully breached OpenAI's systems by chaining three separate vulnerabilities, gaining access to the company's private code repository within 72 hours. OpenAI awarded the team a $6,500 bounty through its Bugcrowd vulnerability disclosure program.

The attack began with a vulnerable libheif library in Discourse, the forum software running on OpenAI's platform, which allowed remote code execution. From there, the researchers exploited a flaw in OpenAI's single sign-on (SSO) system to compromise an employee's ChatGPT account and access the Codex environment connected to OpenAI's GitHub organization. The team opened a harmless pull request to prove access before stopping.

The vulnerability was discovered in late July 2026 and reported through Bugcrowd on July 25. OpenAI patched the issue the same day. Discourse published a security advisory on July 28 with a CVSS severity rating of 8.8. The breach became public knowledge on September 17 when the Wall Street Journal reported on it.

AI Model Accelerated Exploit Development

The researchers initially attempted exploit development using Claude Opus 4.8 but found it unreliable for the task. After switching to Claude Opus 5, which launched July 24, they produced a working ARM64 exploit within hours and subsequently adapted it for x86-64 and jemalloc environments. Memory-corruption exploit development traditionally requires weeks of specialist work by skilled engineers.

Broader Implications for Cryptocurrency

Security firm Chainalysis reported a significant increase in malicious blockchain activity, with daily malicious onchain writes climbing from 2.06 to 11.1—a 440% increase compared to the prior year. The firm attributed the jump to mid-2025, when open-weight Chinese language models launched without meaningful safeguards against generating malicious code.

Attackers are using blockchains as command-and-control infrastructure, a technique known as blockchain dead drops, to post malware instructions on immutable ledgers that cannot be seized or taken offline. State-linked operators from North Korea and Iran account for roughly two-thirds of new activity and approximately half the total.

Researchers tracking North Korea's Kimsuky group discovered local large language model platforms, including Ollama, GPT4All, and Msty, installed on the group's infrastructure alongside AI-generated phishing materials targeting virtual asset and financial investment sectors. Blockaid identified 212 onchain exploits valued at $1.1 billion, and Defillama recorded April 2026 as crypto's most-hacked month on record with 30 incidents.

Industry defenders are anticipating increased pressure, with Coinbase warning that bug bounty programs could face a threefold increase in reports as AI systems flood vulnerability disclosure channels with noise.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $78,078.45+2.45% EthereumETH $2,508.40+3.25% Tether USDUSDT $1.00+0.02% BNBBNB $749.79+3.99% XRPXRP $1.32+2.30% USDCUSDC $1.00+0.01% SolanaSOL $105.68+6.12% TRONTRX $0.3378+0.94% HyperliquidHYPE $90.12+13.48% ZcashZEC $1,463.30+8.78%
Prices by Coinranking. Informational only.