Hacktron AI Researchers Hack OpenAI via Forum Exploit, Earn $6,500 Bug Bounty
On September 18, Ars Technica reported that researchers from Hacktron AI successfully compromised OpenAI systems using a multi-step attack chain. The breach began by exploiting a vulnerability in OpenAI's third-party Discourse forum, then escalated through internal sign-on systems to access an employee's ChatGPT account. Attackers ultimately exfiltrated sensitive code from GitHub and proposed unauthorized code changes before disclosing the findings. OpenAI acknowledged the researchers' report and awarded a $6,500 bug bounty for the discovery. The incident highlights how sequential, low-profile access steps can evade conventional single-request security scanners that do not analyze attack chains across multiple interactions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in