Claude Opus 5 Used to Compromise OpenAI Staff Accounts via Linked Vulnerabilities
Researchers at Hacktron leveraged Anthropic’s Claude Opus 5 to chain two flaws, gaining control of OpenAI employee ChatGPT and Codex accounts and accessing an internal code repository.
Written and published by the Wepro Technology team
A team of three researchers from the security firm Hacktron has demonstrated a sophisticated attack that leveraged Anthropic’s large‑language model Claude Opus 5 to gain unauthorised access to several OpenAI employee accounts.
The first step in the chain exploited a bug in the software that powers OpenAI’s public help forum, allowing the researchers to inject malicious prompts that the model then processed.
Those prompts were crafted to trigger a second vulnerability – a weakness in OpenAI’s own login authentication – which enabled the team to hijack the ChatGPT and Codex accounts of multiple staff members and subsequently retrieve data from an internal code repository.
The incident highlights how AI‑driven tools can amplify traditional software flaws, a concern that resonates with Australian organisations that are increasingly integrating generative AI into their workflows and must therefore tighten their vulnerability management practices.
For Australian IT professionals and students looking to strengthen their defensive skill set, courses such as CompTIA Security+ offered by providers like Wepro Technology can provide the foundational knowledge needed to identify and mitigate similar chained attacks.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime