Claude Opus 5 Used to Compromise OpenAI Staff Accounts via Linked Vulnerabilities
Hacktron researchers employed Anthropic’s Claude Opus 5 to chain two flaws, gaining control of OpenAI staff ChatGPT and Codex accounts and accessing an internal code repository.
Written and published by the Wepro Technology team
Three security researchers from the firm Hacktron have demonstrated a novel attack using Anthropic’s large language model Claude Opus 5, chaining together two separate vulnerabilities to infiltrate OpenAI’s internal systems. The researchers disclosed the findings to highlight how advanced AI tools can be weaponised when combined with software bugs, a concern that resonates across the global cybersecurity community.
The attack began with a flaw in the software that powers OpenAI’s public help forum, allowing the researchers to inject malicious prompts into the system. Those prompts were then leveraged to exploit a weakness in OpenAI’s own login mechanism, effectively bypassing authentication controls and escalating privileges within the organisation’s network.
By chaining these two defects, the team was able to seize control of the ChatGPT and Codex accounts belonging to several OpenAI employees. With those credentials, they accessed an internal OpenAI code repository, exposing proprietary code and underscoring the potential impact of combined AI‑driven and traditional software vulnerabilities.
The incident serves as a stark reminder for Australian IT professionals and students that the security landscape is evolving rapidly, with AI models becoming both tools and targets. Understanding how AI can amplify existing flaws is now a critical component of any robust security strategy, especially for organisations that handle sensitive data or provide cloud‑based services.
For those looking to strengthen their defensive capabilities, Wepro Technology in Darwin offers Security+ and other cybersecurity courses that cover threat modelling, vulnerability assessment, and the secure deployment of AI technologies, helping professionals stay ahead of emerging attack vectors.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime