Claude – Bitcoin Platform https://bitcoinplatform.com Breaking Crypto News and Blockchain updates Sat, 19 Sep 2026 00:40:00 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1.1 https://bitcoinplatform.com/wp-content/uploads/2026/09/cropped-fevi-18-32x32.png Claude – Bitcoin Platform https://bitcoinplatform.com 32 32 Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours https://bitcoinplatform.com/anthropics-claude-helped-3-researchers-breach-openai-in-under-72-hours/ https://bitcoinplatform.com/anthropics-claude-helped-3-researchers-breach-openai-in-under-72-hours/#respond Sat, 19 Sep 2026 00:40:00 +0000 https://bitcoinplatform.com/anthropics-claude-helped-3-researchers-breach-openai-in-under-72-hours/ Security researchers at Hacktron recently leveraged Anthropic’s Claude to breach OpenAI accounts and gain access to an internal code repository within 72 hours. The researchers found vulnerabilities in OpenAI’s identity infrastructure and image-processing pipeline, enabling them to compromise multiple employees’ ChatGPT and Codex accounts.

The attack began with an investigation into the image-upload pipeline used by OpenAI’s Discourse community forum, where a flaw in the processing of HEIC and HEIF files through ImageMagick and libheif allowed for malicious image uploads. Anthropic’s Claude Opus 4.8 identified a heap buffer overflow in the libheif package, leading to code execution when ASLR was disabled.

Despite initial challenges in exploiting the vulnerability reliably, Anthropic released Opus 5, which enabled the researchers to develop a working exploit for both ARM64 and x86-64 architectures. By July 25, the team had successfully executed code through a malicious image upload.

The researchers then tested Claude’s capability to reproduce the attack against a remote environment autonomously. After some adjustments to the test environment, Claude successfully replicated the exploit against the remote system, allowing the researchers to gain administrative access to OpenAI’s community forum.

Subsequently, the researchers used a weakness in OpenAI’s single-sign-on system to escalate their access to ChatGPT and Codex accounts. One compromised Codex account was linked to OpenAI’s GitHub organization, providing the researchers with entry into the company’s internal software environment.

Hacktron disclosed the vulnerabilities to OpenAI, which promptly addressed the identity-side flaw and rewarded the company with a $6,500 bounty. The breach highlighted the speed at which AI is streamlining exploit development processes, reducing the reliance on specialized expertise.

However, the operation still required skilled human researchers to guide the AI models effectively. As AI-powered coding agents like Codex and Claude Code become more prevalent in corporate workflows, the potential blast radius of a compromised account increases, posing significant security risks.

The breach underscored the need for robust security measures as AI lowers the barrier to developing sophisticated exploits. OpenAI and Discourse took steps to tighten access controls and implement additional safeguards around their systems following the disclosure of the vulnerabilities.

In conclusion, the OpenAI breach serves as a wakeup call for organizations to enhance their cybersecurity measures in the face of evolving threats posed by AI-powered exploits.

]]>
https://bitcoinplatform.com/anthropics-claude-helped-3-researchers-breach-openai-in-under-72-hours/feed/ 0
White Hats Used Anthropic’s Claude to Break Into OpenAI in 72 Hours https://bitcoinplatform.com/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours/ https://bitcoinplatform.com/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours/#respond Fri, 18 Sep 2026 14:58:08 +0000 https://bitcoinplatform.com/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours/

Exploring the Chain, Step by Step

A critical vulnerability in the ‘libheif’ library within Discourse, a popular forum software, enabled remote code execution (RCE) within the forum system. Leveraging this flaw, a team of researchers managed to navigate through a weakness in OpenAI’s single sign-on (SSO) process, gaining control of an employee’s ChatGPT account and ultimately accessing the Codex environment linked to OpenAI’s GitHub organization.

This breach provided access to the openai/openai monorepo, where the researchers, associated with the cybersecurity startup Hacktron AI, initiated a benign pull request as proof of their intrusion, refraining from delving into sensitive source code.

The incident unfolded towards the end of July, with the team promptly reporting their findings through OpenAI’s Bugcrowd program on July 25. OpenAI swiftly addressed the vulnerability on the same day, and Discourse issued a security advisory on July 28, rating the severity on the Common Vulnerability Scoring System (CVSS) at 8.8. The breach only became public knowledge on September 17, following a report by the Wall Street Journal.

A Shift in Models Made All the Difference

The noteworthy aspect of this breach lies not in the mere existence of a bug within OpenAI’s system, as software vulnerabilities are commonplace. Rather, the key takeaway is the rapid transition from bug discovery to exploit deployment.

Initially experimenting with Claude Opus 4.8, the team encountered inefficiencies and swiftly switched to Claude Opus 5, which was released on July 24. Within a matter of hours, they successfully crafted an ARM64 exploit, subsequently adapting it for x86-64 and jemalloc environments. Traditionally, the development of memory-corruption exploits demands weeks of skilled labor, yet in this instance, the entire process transpired within a span of three days.

Impact on the Cryptocurrency Realm

Within the realm of cryptocurrency, digital expertise can translate into monetary gains rather than a mere software contribution. Recent data from Chainalysis reveals a surge in malicious activities on public blockchains, with a staggering 440% increase in malware instructions posted globally compared to a year ago. Daily malicious onchain writes have escalated from 2.06 to 11.1, marking a significant spike.

This surge can be traced back to mid-2025, coinciding with the emergence of open-weight Chinese models devoid of robust safeguards against malicious coding. Termed as blockchain dead drops, this tactic involves parking command-and-control instructions on an immutable ledger, impervious to seizure or shutdown. By the second quarter of 2026, state-affiliated actors from North Korea and Iran spearheaded a substantial portion of this illicit activity.

Researchers monitoring North Korea’s Kimsuky entity detected the utilization of local large language model (LLM) platforms like Ollama, GPT4All, and Msty on their infrastructure, alongside AI-generated phishing traps aimed at virtual asset and financial targets. Instances of onchain exploits, valued at $1.1 billion, surged to 212 as AI-driven attacks on wallets intensified. April 2026 marked a record-breaking month in crypto history, with 30 reported hacking incidents.

In response to this escalating threat landscape, entities like Coinbase are bracing for a potential tripling in bug reports as AI inundates disclosure programs with noise. The $6,500 bounty awarded for surfacing a complex three-stage breach underscores the growing commoditization of exploit development services, hinting at a trajectory of increased prevalence in the future.

As the cybersecurity landscape continues to evolve, it is imperative for organizations to bolster their defenses against sophisticated threats and remain vigilant in safeguarding their digital assets.

]]>
https://bitcoinplatform.com/white-hats-used-anthropics-claude-to-break-into-openai-in-72-hours/feed/ 0