Under $3,000 in Tokens: Claude Opus 5 Cracked OpenAI's Internal Repo in Hours
Yuchenj_UW · x · 2026-09-18
Adding detail to the report that three researchers breached an OpenAI employee's Codex account, the author notes they turned an image-upload bug into a full account takeover, then had the compromised employee's Codex open a PR in OpenAI's internal monorepo. The whole attack cost under $3,000 in tokens. Opus 4.8 struggled with the exploit; Opus 5 cracked it within hours of release. His takeaway: AI-powered cyberattacks are becoming common and cheap, so the best defense is putting the best AI in defenders' hands too.
Related event: Researchers Used Claude to Breach OpenAI's Internal Codebase(22 posts)→
More from Safety
- Air-gapping is leakier than you think: LED exfil at 100 kbps and dozens of side channels — dioscuri · 2026-09-18
- NHTSA developing federal ADS performance standard as US preps for larger-scale Robotaxi rollouts — Scobleizer · 2026-09-18
- Models fill in blanks: a pre-execution gate that strips verdict authority from LLMs — Jay299792458 · 2026-09-18
- tszzl: Weight self-exfiltration can only be done at the lab, not via side channels — tszzl · 2026-09-18
- That viral "air-gapped data exfiltration" paper only read temperature over a 4cm gap — basedjensen · 2026-09-18
- New paper shows models can fingerprint and exploit inference engines like vLLM using output tokens alone — chaumian · 2026-09-18