연구자들이 Claude로 OpenAI를 뚫었다 — 사진 한 장으로 사내 저장소까지, 포상금은 6,500달러
보안 연구팀이 Anthropic의 Claude Opus 5로 OpenAI 직원 계정을 통째로 장악한 과정을 공개했다. 시작은 이미지 한 장이었다. HEIC 사진을 OpenAI 커뮤니티 포럼에 올려 서버에서 코드를 실행하고, 여기에 OpenAI의 SSO 취약점을 엮어 직원들의 ChatGPT·Codex 계정을 손에 넣었다. 그 계정에 연결된 Outlook·Slack·GitHub까지 닿았고, 마지막엔 장악한 직원의 Codex로 OpenAI 사내 monorepo에 실제 PR을 열어 접근이 진짜임을 증명했다. 걸린 시간 72시간 미만, 토큰 비용 3,000달러 미만. 관찰자들은 이전 모델 Opus 4.8은 이 익스플로잇에서 헤맸는데 Opus 5가 나오자 몇 시간 만에 풀어냈다는 점을 짚었다. OpenAI는 최초 신고 약 14시간 만에 SSO 구멍을 막았고, 연구팀에 준 포상금은 6,500달러였다.
댓글 반응
답글은 두 갈래였다. 하나는 포상금 조롱이다. "72시간 나눠서 시급 30달러, 웬만한 나라 최저임금보다 낮다", "이건 포상금이 아니라 팁이다", "펜테스트 보고서 하나도 이 값엔 사인 안 한다"가 줄줄이 달렸다. 다른 하나는 무게다. "계정을 훔치면 보통 남이 메일을 읽는 정도인데, 이번엔 코딩 에이전트가 딸려 왔다", "SSO 우회가 진짜 핵심이었다"는 지적. 방어 쪽도 최고 성능 AI를 쥐어야 한다는 원 저자의 결론에 동의가 모였다.
출처 5건 보기· @S1r1u5_, @Yuchenj_UW, @WatcherGuru 외 2
- @S1r1u5_On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵X ♥9.7천
- @Yuchenj_UWOK, this is a big deal: 3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo. Their entire hacking cost less than $3000 in tokens. Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours. AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.X ♥780
- @WatcherGuruJUST IN: OpenAI hacked by researchers using Anthropic's AI models, FT reports.X ♥5.6천
- @WSJA bug-hunting independent security research team used Anthropic’s Claude software to gain access to an OpenAI employee’s ChatGPT account, giving them a way to read and suggest changes to the company’s private cache of software.X ♥809
- @polymarketjapan【速報】研究者、Claudeを使いOpenAI社員のChatGPTに侵入 OpenAIへ報告し、バグ報奨金6500ドルを受領X ♥4.8천