A small group of cybersecurity researchers announced on Sunday that they breached OpenAI earlier this year, adding to the rising concerns about the security and safety of artificial intelligence.
Details of the Breach
The researchers from a company called Hacktron found that by chaining two unknown vulnerabilities, one in a third-party company called Discourse and the other in the way OpenAI verifies employee identities, they could access the ChatGPT accounts of employees. These researchers, known as "white hat hackers," did not cause any harm to the company's systems.
Read more: Makam Improves with Investment in AI
The Hacktron operation took place over 72 hours in late July, shortly after some OpenAI representatives were unshackled from restrictions and breached the Hugging Face AI platform. A spokesperson for OpenAI confirmed that Hacktron had submitted a report on the breach and stated that the vulnerabilities have now been fixed. The spokesperson said, "We thank the researchers for reaching out and sharing their findings."
Public Concerns About AI Safety
This news comes at a time when concerns about AI safety have significantly increased in recent weeks. Safety researchers have resigned from major companies and issued serious warnings about the potential dangers of this advanced technology to humanity, while politicians from various political spectrums have called for action. While most of these concerns focus on the capabilities of advanced AI models, the security of the companies themselves is also a significant issue.
The development of AI is highly competitive, and there are concerns about theft, especially through a known process called distillation. Like many companies, OpenAI has a program to reward bug discoverers, paying cybersecurity researchers who find new ways to breach its systems. The Hacktron researchers wrote in their blog post that OpenAI paid them $6,500 for this discovery.
There is no evidence that other hackers have exploited the vulnerabilities used by Hacktron. However, U.S. officials have accused China of economic espionage for years, claiming that Chinese state hackers regularly share stolen trade secrets with Chinese companies. China generally denies these allegations.
Greg Linares, a cybersecurity researcher at Persona, stated that Hacktron's findings could allow elite hackers from China or other countries to breach OpenAI's systems. He said, "What they connected is not unusual and could be used by real high-level hackers, such as APTs or state-sponsored hackers, to infiltrate targets."
Read more: OpenAI Reveals Six Concerning Behaviors of Its Models · Release of AI Infrastructure Contracts by Anthropic and OpenAI



