Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
- ID
- 26307
- Status
- summarized
- Published
- 20 Sep 2026, 2:36 AM
- Fetched
- 20 Sep 2026, 5:39 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 20 Sep 2026, 5:40 AM
- Tags
- Audience
- developersai_ml_learnersai_agent_userssaas_startup_founders
What happened
Security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws—a bug in OpenAI's Discourse-based public help forum and a weakness in OpenAI's shared SSO login system—to take over ChatGPT and Codex accounts of OpenAI staff and reach an internal code repository in under 72 hours. The root cause was that OpenAI's forum used the same 'Sign in with OpenAI' SSO as staff systems, so compromising the forum server gave access to staff accounts without any action from victims. OpenAI fixed the issue in ~14 hours and paid a $6,500 bounty on September 1, while noting the award covered the OpenAI-side finding, not the Discourse testing.
Why it matters
If you run a single sign-on system shared between public-facing community surfaces (forums, help centers) and internal staff tools, a compromise of the lower-trust surface can cascade into staff account takeover with zero user interaction. Audit whether your SSO provider or architecture isolates community/external identities from internal staff identities, and consider whether AI-assisted chaining of low-severity bugs could expose paths you haven't mapped.
Discussion angle
How AI models like Claude Opus 5 are becoming practical tools for chaining vulnerabilities that individually look low-severity—does your threat modeling account for an adversary that can automate multi-step exploit reasoning across your stack?