Press Space to continue
Finding signal on Twitter is more difficult than it used to be. We curate the best tweets on topics like AI, startups, and product development every weekday so you can focus on what matters.
Press Space to continue
Press Space to continue
Initiate AI hyperventilating (already heard on CNN and CNBC on 10 min drive) and no one (MSM) is reporting that this was a basic OpSec failure. Known: CVE, patch-level problem, broken implementation at OAI SSO.… They need to pause. Hire the right Security team. Be Engineers.
SITUATION EXPLAINED: Three guys hacked OpenAI in 72 hours using Claude. • Three researchers at Hacktron AI chained two vulnerabilities to take over multiple OpenAI employees' ChatGPT and Codex accounts, reaching the private GitHub monorepo in 72 hours • The entry point was an image decoder. OpenAI's forum runs on Discourse, which uses FastImage for image checks, but FastImage doesn't support HEIF, so it passed those files to ImageMagick and exposed the libheif parser • That same library is used in Slack, Meta, GitHub Enterprise, and Ruby on Rails • They stopped without downloading source code and filed a harmless pull request as proof. It wasn't accepted • Hacktron's blog post: "Opus 4.8 struggled across several sessions to produce a working exploit. Within hours of Opus 5's release, we gave it the same problem and it succeeded" • It cost under $3,000 in tokens. OpenAI fixed it in 14 hours and paid $6,500 @theojaffee: "$6,500 sounds like way too low. It should be, like, 1,000 times more than that. If they decided to sell this bug to the Chinese government instead, so the Chinese government would be able to scrape OpenAI's entire monorepo, what do you think they would pay for it? $100 million?"