WSJ: Three Attackers Plus Claude and Codex Stole OpenAI's Algorithmic Secrets, Not Weights
trevposts · x · 2026-09-18
A debate over the reported theft of OpenAI's algorithmic secrets: Sneha Revanur relays a WSJ report saying three individuals, using Claude and Codex, obtained only the "secret sauce" (OpenAI's algorithmic secrets) rather than the "crown jewels" (the model weights). She doubts Chinese threat actors haven't gotten further, arguing that racing faster only creates an illusion of a lead, and that serious frontier security would mean following through on export controls and pacing so labs make wiser speed-vs-security trade-offs.
The quoted post claims that on July 25 they "hacked OpenAI": two bugs let them take over ChatGPT/Codex accounts of OpenAI employees (plus some unaffiliated users) and reach connected services like Outlook, Slack and GitHub, proving it with a PR in OpenAI's internal codebase—all in under 72 hours.
Related event: Researchers use Claude to breach OpenAI's internal codebase(19 posts)→
More from Safety
- Australia proposes law forcing AI companies to report rogue incidents by early 2027 — gaganghotra_ · 2026-09-18
- Martin Casado on Noam Brown's air-gap warning: covert channels are an old, understood problem — tszzl · 2026-09-18
- HEIF Heist: one image parser bug class hits OpenAI, Slack, Meta, GitHub Enterprise with RCE — Miles_Brundage · 2026-09-18
- Commentary: orgs still treat AI like SaaS, and SaaS security posture is terrible — soumitrashukla9 · 2026-09-18
- David Sirota: AI CEOs will make products safe only when jail and bankruptcy loom — michael_nielsen · 2026-09-18
- Air-gapped AI exfiltration debate: no bits move without a matching receiver stack — basedjensen · 2026-09-18