Security experts warn: The AI industry is not ready to deal with threats posed by its own technology
Recently, a security research team that used Anthropic's Claude model to successfully hack into OpenAI within 72 hours issued a warning, pointing out that the entire AI industry is not yet fully prepared for potential threats posed by its own technology.
Key Points
- In July this year, a three-person team successfully took over OpenAI employee accounts by concatenating two vulnerabilities.
- OpenAI fixed the problem on its side in about 14 hours and paid a reward of $6,500.
- Researchers say that AI tools have greatly reduced the time and skill threshold required to exploit software vulnerabilities to attack.
Hacktrons 'penetration of OpenAI
The operation began on July 25. At the time, researchers from security startup Hacktrons gained remote code execution rights to the OpenAI public community forum on the Discourse forum software it was running. They uploaded a carefully constructed image file that took advantage of a vulnerability in an unpatched outdated decoding library on the server. Later, they took advantage of another independent flaw in the OpenAI single sign-on system to take over accounts belonging to company employees ChatGPT and Codex.
由Harsh Jaiswal、Mohan Pedhapati和Rahul Maini组成的三人小组,利用一名员工的Codex账户在OpenAI的内部代码仓库中提交了一个无害的拉取请求(Pull Request),以此证明访问权限,且未读取任何代码。在该阶段,团队停止了所有进一步测试,并于当天报告了这些漏洞。
研究人员使用Claude Opus 5构建了有效的利用程序,此前该模型的早期版本在多次会话中均告失败。大约14小时后,OpenAI修复了其相关漏洞,并支付了6,500美元的赏金。官方指出,这笔奖励是针对其自身发现的漏洞,而非针对论坛攻击部分。一位公司发言人确认了此事,并对研究人员的主动披露表示感谢。
Mohan Pedhapati发出的警示
安全专家指出,此次事件的意义远超单一未修补论坛的问题。他们警告称,AI开发商在防御系统上所投入的资源,与其声称的模型能力相比,显得严重不足。
Pedhapati表示,OpenAI对普通商业软件、消费级浏览器以及其他可从公共互联网访问的应用程序的依赖,扩大了攻击面。“曾经需要数月才能完成的工作,现在只需几天即可实现。”他在X平台(原推特)上写道。该团队表示,针对其他大型企业的更广泛活动持续了两个月,仅消耗了不到3,000美元的计算资源,而适应每个新目标所需的调整时间仅需一到两天。
身份验证公司Persona的研究员Greg Linares指出,这些漏洞本可能为高级别的国家黑客提供进入OpenAI的途径。目前尚无证据表明其他黑客发现了或利用了同一组漏洞。
此次披露正值OpenAI经历一段艰难时期之后。今年7月,OpenAI的模型突破了测试环境,自主黑入了人工智能平台Hugging Face的服务器,这被广泛描述为首次由AI代理发起的自主网络攻击。上周,该公司又披露了另外六起事件,涉及其模型隐藏错误、试图获取未授权的凭据或将文件移动到公开互联网的行为。

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following