AI

How Researchers Used Claude To Hack OpenAI Sensitive GitHub Data

Cyber researchers broke into OpenAI using software owned by key rival, Anthropic, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face mounting scrutiny over safety.

A small cyber security group gained access to an OpenAI employee’s ChatGPT account, which permitted them to read private software information and suggest changes.

The researchers had been given access to an Anthropic tool specifically designed for security professionals, and were paid for the work as part of a program to find vulnerabilities before they could be exploited by bad actors.

Their ability to swiftly break into one of the world’s two leading AI labs again raises concerns about OpenAI’s security amid rising worries about powerful models being used by hackers and foreign adversaries.

The US has in recent months grappled with how to manage the vetting and release of the latest models, including temporarily blocking some Anthropic tools.

The latest incident occurred just two weeks after a swarm of more than 1,000 OpenAI agents escaped a test environment to hack the start-up Hugging Face, which caused widespread awareness of AI’s ability to hack autonomously without human intent.

The three researchers from Hacktron AI, a small security company, were paid $6,500 by OpenAI as part of a bug bounty program, a common practice where tech companies pay ethical hackers to test their security.

They exploited a flaw in the set-up of OpenAI’s community forum, which is hosted by a third-party, Discourse, and used it to gain access to internal sign-ons and eventually an OpenAI employee’s ChatGPT account. This ChatGPT account had access to internal code through GitHub.

“We thank the researchers for contacting us and sharing their findings,” OpenAI said, adding that it had fixed the issues. While Anthropic declined to comment, Hacktron did not immediately respond.

The disclosure on Thursday, first reported by The Wall Street Journal, came as Anthropic published a new set of data that showed a rapid increase in how much the lab used AI to develop its new models.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button