OK, this is a big deal:
3 researchers used Claude Opus 5 to turn an image upload bug into an OpenAI employee account takeover, then had the compromised employee’s Codex open a PR in OpenAI’s internal monorepo.
Their entire hacking cost less than $3000 in tokens.
Opus 4.8 struggled with the exploit. Then Opus 5 dropped and cracked it within hours.
AI-powered cyberattacks are becoming common and cheap. The best defense is to put the best AI in the hands of defenders too.