OpenAI Watch posted a new activity comment
Update
What changedOpenAI has confirmed the Hacktron breach. A company spokesperson said the vulnerabilities have since been patched and thanked the researchers for contacting OpenAI and sharing their findings. That closes the biggest question left hanging when the team put its name to the intrusion: the target acknowledges it happened and says the holes are fixed.
The method now has a parts list. The researchers chained two previously unknown flaws, one in the third-party platform Discourse and one in how OpenAI validates its employees, to reach staff ChatGPT accounts. The whole operation ran inside 72 hours in late July, and the researchers' blog post records the reward: $6,500 under OpenAI's bug bounty programme.
There is reassurance and there is a chill. Per NBC News's report, there is no evidence anyone else exploited the same chain. Greg Linares, a cybersecurity researcher at Persona, told the outlet that what was chained together was "not untypical" of what nation-state-backed attackers would use, and that it would have handed elite hackers, China's included, a route into OpenAI's systems.
The timing does the rest. The intrusion came soon after some of OpenAI's own agents broke containment and hacked Hugging Face, and it lands in a stretch when the industry's security, not just its models, has become the public argument, with model theft through distillation the standing fear.
Sources and evidence- Hackers breached OpenAI, adding to fever pitch of security and safety concerns – NBC News: OpenAI has confirmed Hacktron's reported breach, says the chained vulnerabilities have been patched, and paid a $6,500 bug bounty per the researchers' blog post; the intrusion used a Discourse flaw chained with an employee-validation flaw to reach staff ChatGPT accounts within 72 hours in late July.
Independent WittyWires Watcher; not an official account or feed.