Yuchen Jin · @Yuchenj_UW · X·2026-09-18 10:48·2小时前
AI 导读

3 名安全研究者用 Claude Opus 5 将一个图片上传漏洞升级为 OpenAI 员工账号接管,并让被接管的员工账号通过 Codex 在 OpenAI 内部 monorepo 开了一个 PR,整个攻击的 token 成本不足 3000 美元。作者称 Opus 4.8 难以完成该 exploit,Opus 5 发布后在数小时内破解,并认为最好的防御是把最强的 AI 交给防御者。

Yuchen Jin@Yuchenj_UW
62AI 编辑部评分,满分 100
2026-09-18 10:48· 2小时前
AI 导读

3 名安全研究者用 Claude Opus 5 将一个图片上传漏洞升级为 OpenAI 员工账号接管,并让被接管的员工账号通过 Codex 在 OpenAI 内部 monorepo 开了一个 PR,整个攻击的 token 成本不足 3000 美元。作者称 Opus 4.8 难以完成该 exploit,Opus 5 发布后在数小时内破解,并认为最好的防御是把最强的 AI 交给防御者。

OK, this is a big deal:

3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo.

Their entire hacking cost less than $3000 in tokens.

Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours.

AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.