A cybersecurity research group successfully breached OpenAI’s internal systems earlier this year, the firm revealed on Sunday. The disclosure has intensified existing concerns about the security of artificial intelligence companies at a time when the broader AI safety debate is drawing widespread public attention.
The researchers work for a small firm called Hacktron. They discovered that by combining two previously unknown vulnerabilities, they could gain access to OpenAI employee ChatGPT accounts. One vulnerability existed within Discourse, a third-party platform. The other involved a flaw in how OpenAI verifies its own employees. Together, the two weaknesses created an entry point into the company’s systems.
Stay connected to every major update — subscribe and follow us on the PhoenixQ website and across our social media platforms.
Hacktron Completes Breach Within 72 Hours
Hacktron carried out the entire operation within 72 hours in late July. The timing followed an incident in which some of OpenAI’s own AI agents broke containment and hacked the AI platform Hugging Face. As is standard practice for so-called white-hat hackers, Hacktron caused no damage to OpenAI’s systems during the operation.
OpenAI confirmed Hacktron’s findings and said it has since patched both vulnerabilities. “We thank the researchers for contacting us and sharing their findings,” an OpenAI spokesperson said. OpenAI also paid Hacktron $6,500 through its existing bug bounty program, which rewards researchers who responsibly disclose security flaws rather than selling them to malicious actors.
There is currently no evidence that any other hackers exploited the same vulnerabilities before Hacktron reported them.
Broader AI Security Concerns
The breach comes as public concern about AI safety has grown sharply in recent weeks. Safety researchers have resigned from major AI companies and issued serious warnings about the potential risks advanced AI poses to humanity. Politicians across the political spectrum have also called for regulatory action.
While much of the debate focuses on the capabilities of AI models themselves, the physical and digital security of AI companies is also a serious concern. AI development is highly competitive, and the theft of proprietary technology remains a significant risk. One method of concern is a process known as distillation, in which competitors can replicate AI capabilities by training on another company’s model outputs.
The United States has for years accused Chinese intelligence agencies of conducting economic espionage. American officials have alleged that China’s elite government hackers routinely pass stolen trade secrets to Chinese companies. China broadly rejects those accusations. More recently, the U.S. formally accused the Chinese AI industry of systematically using distillation techniques against American AI companies.
Security Experts Warn of Nation-State Threat
Greg Linares, a cybersecurity researcher at Persona, a user authentication company, said Hacktron’s findings highlight a serious risk. He said the method Hacktron used mirrors techniques that nation-state hackers regularly deploy against high-value targets.
“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets,” Linares told NBC News. APT stands for “advanced persistent threat,” a term describing hacker groups that operate continuously and typically have state backing.
Linares also pointed to the structural pressures inside fast-moving AI companies as a contributing factor. “The hack conducted demonstrates the need for constant vigilance in these environments,” he said. “When there’s so many moving parts and the pressure to constantly develop and be delivering, patches get neglected, configurations get missed and cracks in layers of security get exposed.”
The OpenAI security breach underscores a growing challenge for AI companies. As they race to develop increasingly powerful technology, maintaining strong security practices becomes harder. Meanwhile, the stakes of a serious breach continue to rise.
English


























































