第一财经

A team of three, led by Claude, has cracked into OpenAI's internal code repository.

原文:三人团队、一个Claude,攻破OpenAI内部代码库

AI-Assisted Hacker Attack on OpenAI: A Security Incident Caused by a Small Team of Three

Summary of Key Points

In simple terms, this incident involved a small team of three individuals who, with the help of AI, successfully hacked into OpenAI’s internal systems “legally” within 72 hours.

This was not a fictional hacker battle from a movie but a legitimate “bug bounty” test. However, it caused a sensation because it challenged two traditional perceptions:

1. Reduced barriers to entry: What used to require top security experts, large teams, and months of effort to accomplish through complex penetration tests can now be done by a few people in just a few days with the assistance of AI.

2. The role of AI: AI is no longer an uncontrolled entity; it has become an extremely powerful tool in the hands of humans, capable of writing code, identifying vulnerabilities, and exploring attack paths.

Although OpenAI only paid a reward of $6,500, the incident prompted 25% of its engineers to focus on fixing the vulnerabilities. This indicates that the rules of cybersecurity are changing, as AI is bringing high-level security challenges down to a more accessible level for everyone.

---

Detailed Analysis

1. The Truth of the Incident: It Was a Human-AI Collaboration, Not AI Going rogue

First, let’s clarify the biggest misconception: AI did not attack OpenAI on its own. The attackers were researchers from the cybersecurity startup Hacktron AI, participating in OpenAI’s bug bounty program, which is essentially an official initiative that rewards findings of security vulnerabilities. Therefore, the entire process was legal and authorized.

So, what was the role of AI in this attack?

  • Traditional approach: Human hackers discover a vulnerability → Write code to exploit it → Analyze the next steps.
  • New approach: Human hackers discover a vulnerability → Use AI (Claude) to generate the exploit code → Let AI analyze the vulnerability logic → Humans proceed based on the AI’s recommendations.

The Hacktron team consisted of only three people. They utilized the Anthropic company’s Claude model, specifically the newly released Opus 5 version, to quickly generate the attack code. AI acted like an inexhaustible and knowledgeable assistant, eliminating the time-consuming and tedious tasks of writing code and deducing attack strategies.

To put it simply: It’s like a top chef (a human expert) who used to do all the preparatory work—shopping, washing, chopping, and cooking the food. Now, the chef still does the cooking, but he has a super-intelligent robot assistant that automatically handles the chopping and seasoning, allowing the chef to just taste the dish before serving it. The efficiency has increased, but the chef still retains control.

2. The Attack Path: From a Forum Image to the Core Code Repository

The attack path was ingenious and revealed a common issue in large tech companies’ security setups:

1. Entrance point: An inconspicuous forum image. OpenAI uses a third-party software called Discourse for its community forum. Hacktron found a vulnerability in how Discourse handled certain image files. It’s like having a strong door lock but an unsecured window through which a thief could climb in.

2. Breakthrough: The researchers used Claude to write code to exploit this vulnerability. Initially, it didn’t work, but the next day, the new version of Claude (Opus 5) found a solution, and the generated code successfully allowed them to access the forum server.

3. Unexpected discovery: They obtained “universal access tokens.” These tokens were intended for the forum, but some of them belonged to OpenAI employees. Worse still, these tokens granted access not only to the forum but also to OpenAI’s internal GitHub repository, where the company’s core algorithms and software code were stored.

4. Further intrusion: Using one of the employees’ ChatGPT accounts, the researchers entered OpenAI’s “Monorepo”—a central repository for all its code. Although it didn’t contain the most critical model parameters, it still contained a lot of important code. The researchers even submitted a code change request, proving they had legitimate access.

Why such access? OpenAI’s permission management was too lax; the tokens used for forum login granted too much access, violating the principle of “least privilege” (i.e., the user should only have the necessary permissions).

3. How Three People Could Do It: How AI Lowered the Attack Barriers

This is the most thought-provoking aspect of the incident:

  • Traditional barriers to security attacks:
  • Expertise: Require knowledge of network protocols, operating systems, and application-layer vulnerabilities.
  • Time: Analyzing complex vulnerabilities could take weeks or months.
  • Tools: Expensive specialized tools and infrastructure were needed.
  • Changes brought by AI:
  • Code generation: Claude Opus 5 could quickly generate usable exploit code based on the vulnerability description. Previously, this would have taken senior engineers days; now, AI can provide a feasible solution in minutes.
  • Logical reasoning: AI can analyze the logic behind vulnerabilities, accelerating the analysis process.
  • Path exploration: AI helps in trying different attack paths, such as testing alternative tokens or identifying additional injection points.

As a result, a small team of three, with access to AI services, completed what would have previously required a professional team of ten over several weeks. This suggests that in the future, many “non-professional” hackers could pose a threat to large systems with the help of AI.

4. OpenAI’s Response: The $6,500 Bounty and the Significant Impact

OpenAI only paid $6,500, but the impact was significant:

  • Public response:
  • Acknowledged two issues: the Discourse vulnerability and a configuration error in OpenAI’s SSO (Single Sign-On) system.
  • Fixed the vulnerabilities: Discourse was patched immediately, and OpenAI tightened the token permissions and revoked the affected tokens.
  • Paid the bounty.
  • Internal response:
  • 25% of production engineers were assigned to security efforts: Greg Brockman, OpenAI’s president, mentioned that a quarter of the company’s engineers were involved in the response.
  • Comprehensive audit: OpenAI conducted a thorough audit and discovered additional serious security issues. This indicates that the incident might have exposed deeper vulnerabilities.

Why such a strong response? Because the incident showed that traditional defense strategies might no longer be effective:

  • Traditional assumptions: It was assumed that attackers would struggle to break through the first line of defense (e.g., the forum).
  • AI’s impact: AI enables attackers to quickly and accurately bypass defenses and exploit internal vulnerabilities, potentially leading to serious consequences such as data theft or system manipulation.

5. The Future of Cybersecurity with AI

This incident is not an isolated case but a reflection of a broader trend:

  • Dual roles of AI: AI can be used both for attacks and defenses. Companies can use it to automatically detect and fix vulnerabilities, while attackers can use it to bypass defenses.
  • Failure of traditional defenses: Complexity is no longer a barrier; AI can quickly understand complex systems and find vulnerabilities.
  • Reduced need for specialized expertise:普通人 with AI can become a threat.
  • Implications for companies:
  • Strict permission management: Permissions must be strictly controlled; forum login tokens should not grant access to code repositories.
  • AI-assisted security: Companies need to use AI to monitor and repair vulnerabilities automatically.
  • Re-evaluation of risks: The threat no longer comes solely from top hackers; a small team with AI can be a serious threat.
  • Third-party risks: Companies must manage third-party components more carefully, as they can be a vulnerability vector.

In conclusion, this incident is a warning that AI is transforming cybersecurity from a domain for experts to one that affects everyone. Companies must rethink their security strategies and rely less on complexity and expertise as barriers. Individuals should also be aware that while AI offers many benefits, it also brings new risks.