Claude helped hackers take over an OpenAI employee account

AI in 10

AI in 10
Claude helped hackers take over an OpenAI employee account
Sep 17, 2026
OpenAI’s security isn’t just about the model—it’s about every library and login system around it. This breach shows how an AI assistant can compress days of exploit work into hours, and why your data’s safety depends on more than passwords. A white-hat team used Anthropic’s Claude to help chain a multi-step attack: a malicious image triggering libheif RCE, then an OpenAI SSO/session weakness to hijack an employee’s ChatGPT/Codex access and pivot into internal GitHub, Slack, and email. They disclosed it responsibly and OpenAI paid a ~$6,500 bounty, but the speed and method are the real warning. We’ll break down the exploit chain, what “AI-assisted hacking” changes, and what it means for anyone relying on ChatGPT at work. New AI news every weekday — subscribe so you don't miss tomorrow's story.

Referenced Links:
Hacker News discussion (front page)
Reddit: r/technology discussions
Reddit: r/artificial discussions
OpenAI Bug Bounty program


💬 Send Chuck a comment about this episode

Support the show

Want to go deeper with AI? A community of professionals is learning AI together right now at aihammock.com — show notes, links, tools, and real conversations about how to actually use AI in your life.