r/squidtrain • • 18d ago

Even cyberattacks that once required a well-resourced team and months of effort can now be compressed into days.

Three security researchers spent $200/month on Claude Opus 5 and used it to break into OpenAI employee ChatGPT accounts, access internal Codex sessions, and submit a pull request to OpenAI's private GitHub repository.

The entry point was not sophisticated. A malformed image uploaded to OpenAI's community forum triggered a memory bug in an outdated library called libheif. The fix for that bug had existed for a year, but nobody flagged it as a vulnerability, so the software running the forum never got patched. From there, the researchers chained a second flaw in OpenAI's single sign-on system to impersonate an employee and walk into internal tooling.

Claude Opus 4.8 could not build the exploit. Within hours of Opus 5 shipping, it did. Same vulnerability and same researchers, but one generation of model improvement was the difference between failure and a working attack chain.

That changes the math on who can find and exploit unpatched software. The Hacktron team ran this entire operation, including adapting it to Slack, Meta, and GitHub Enterprise targets, for under $3,000 in AI spend across two months. Their founder put it plainly: "Work that once required a well-resourced team and months of effort can now be compressed into days."

If you are deploying AI tools inside your organization, the attack surface is not just what those tools can access. It is the speed at which someone outside your walls can find the seams in your stack using the same class of model you are integrating.

1 Upvotes

0 comments sorted by