{"id":78341,"date":"2026-09-18T11:04:06","date_gmt":"2026-09-18T11:04:06","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours\/"},"modified":"2026-09-18T11:04:06","modified_gmt":"2026-09-18T11:04:06","slug":"white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours\/","title":{"rendered":"White Hats Used Anthropic&#8217;s Claude to Break Into OpenAI in 72 Hours"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Hacktron AI reported the OpenAI chain through Bugcrowd on July 25, 2026, and collected a $6,500 bounty.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Claude Opus 5 produced a working ARM64 exploit in hours after Opus 4.8 failed the same task.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Chainalysis logged 11.1 malicious onchain writes a day, up from 2.06, as open models spread.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>The Chain, Link by Link<\/h2>\n<p>A <a href=\"https:\/\/venturebeat.com\/security\/openai-hacked-by-small-team-of-white-hat-security-researchers-using-anthropics-claude-opus-5\" target=\"_blank\" rel=\"noopener noreferrer\">vulnerable \u2018libheif\u2019 library<\/a> inside Discourse, the forum software, allowed remote code execution (RCE) on the forum itself. From there the team pivoted through a flaw in OpenAI\u2019s single sign-on (SSO) flow, took over an employee\u2019s ChatGPT account, and reached the Codex environment wired to OpenAI\u2019s GitHub organization.<\/p>\n<p>That opened the openai\/openai monorepo, from where the researchers (affiliated with the security startup Hacktron AI) opened a harmless pull request to prove they were inside and stopped short of examining sensitive source code.<\/p>\n<p>The work happened in late July, with the team reporting the developments through OpenAI\u2019s Bugcrowd program on July 25 and the vulnerability was fixed the same day; Discourse published its advisory on July 28 with a Common Vulnerability Scoring System (CVSS) severity of 8.8, and the whole thing only became public on Sept. 17 when the <a href=\"https:\/\/www.wsj.com\/tech\/ai\/hackers-used-anthropics-claude-to-break-into-openai-b40ba883\" target=\"_blank\" rel=\"noopener noreferrer\">Wall Street Journal<\/a> reported it.<\/p>\n<h2>A Model Change Was All That Was Needed<\/h2>\n<p>The interesting part is not that OpenAI had a bug because every software company encounters them from time to time. It is what closed the gap between finding one and weaponizing it.<\/p>\n<p>The team first tried Claude Opus 4.8 but found it unreliable for the task. They then switched to Claude Opus 5, released July 24, and produced a working ARM64 exploit within hours, then adapted it for x86-64 and jemalloc environments. Memory-corruption exploit development is specialist work that has historically taken skilled humans weeks, but in this case, the entire series of events unfolded in less than three days.<\/p>\n<h2>Implications For Crypto<\/h2>\n<p>Crypto is where such digital proficiency can show up as money rather than a simple pull request. Numbers-wise, Chainalysis <a href=\"https:\/\/www.chainalysis.com\/blog\/etherhiding-blockchain-dead-drops\/\" target=\"_blank\" rel=\"noopener noreferrer\">reported this week<\/a> that attackers all over the world are posting malware instructions to public blockchains 440% more often than a year ago, with daily malicious onchain writes climbing from 2.06 to 11.1.<\/p>\n<p>The firm tied the jump to mid-2025, when open-weight Chinese models launched without meaningful guardrails against writing malicious code, and called the technique blockchain dead drops, i.e., command-and-control instructions parked on a ledger that no one can seize or take offline. By the second quarter of 2026, state-linked operators from North Korea and Iran were accounting for roughly two-thirds of new activity and about half the total.<\/p>\n<p>Researchers tracking <a href=\"https:\/\/news.bitcoin.com\/security\/report-north-koreas-kimsuky-turns-ai-into-a-crypto-hacking-weapon\/\">North Korea\u2019s Kimsuky<\/a> found local large language model (LLM) platforms, including Ollama, GPT4All and Msty, installed on the group\u2019s infrastructure alongside AI-generated phishing decoys aimed at virtual asset and financial investment targets. Blockaid counted <a href=\"https:\/\/news.bitcoin.com\/security\/security-firm-blockaid-says-212-onchain-exploits-stole-1-1b-as-ai-and-wallet-attacks-accelerate\/\">212 onchain exploits<\/a> worth $1.1 billion as AI and wallet attacks accelerated, and Defillama recorded April 2026 as crypto\u2019s <a href=\"https:\/\/news.bitcoin.com\/defillama-confirms-april-2026-as-cryptos-most-hacked-month-with-30-incidents\/\">most-hacked month<\/a> on record with 30 incidents.<\/p>\n<p>The ones defending themselves from these attacks are feeling the heat ever more increasingly, with Coinbase recently warning that <a href=\"https:\/\/news.bitcoin.com\/security\/coinbase-says-bug-reports-could-triple-as-ai-adds-security-noise\/\">bug reports could triple<\/a> in the near future as AI floods disclosure programs with noise, which is the awkward corollary of a $6,500 bounty being enough to surface a three-stage chain into a major lab.<\/p>\n<p>Regardless, exploit development is becoming a major commodity service and if the numbers are anything to go by, its prevalence will only keep increasing.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/openai-hacked-white-hat-researchers-anthropic-claude-opus-5\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Hacktron AI reported the OpenAI chain through Bugcrowd on July 25, 2026, and collected a $6,500 bounty. Claude Opus 5 produced a working ARM64 exploit in hours after Opus 4.8 failed the same task. Chainalysis logged 11.1 malicious onchain writes a day, up from 2.06, as [&hellip;]<\/p>\n","protected":false},"author":3947362404,"featured_media":78342,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78341"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/3947362404"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78341"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78341\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78342"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}