• AI Fire
  • Posts
  • 🚨 Researchers Hack OpenAI With Claude!

🚨 Researchers Hack OpenAI With Claude!

GPT-6 Astra Solves 85-Year Enigma

In partnership with

ai-fire-banner

One image, Claude Opus 5, and under 72 hours: how security researchers reached OpenAI employee accounts and internal GitHub repositories.

IN PARTNERSHIP WITH LYNOTE

Drop in a PDF, a document, or your own messy research. Lynote turns it into structured notes you can actually write from.

Draft from those notes, then humanize, and the built-in detector runs a before-and-after comparison, highlighting the exact sentences that still read as machine-written. Every other workflow means pasting between three separate tools and guessing. This is one screen, and it tells you when you're done.

Handles ChatGPT, Claude, Gemini and DeepSeek output. 100+ languages.
Free to start, no card, no signup.

We're live on Product Hunt this Tuesday, Sept 16. Come say hi.

AI INSIGHTS

researchers-use-claude-ai-to-hack-openai-employee-accounts

Security researchers at Hacktron used Anthropic’s Claude Opus 5 to turn an image-processing bug into a working attack against OpenAI. In under 72 hours, they reached employee ChatGPT accounts and OpenAI’s internal GitHub repositories.

The attack combined:

  • A malicious HEIC image that triggered a bug in libheif.

  • OpenAI’s Discourse forum, which used the vulnerable library.

  • An OpenAI SSO flaw that exposed ChatGPT and Codex accounts.

  • A connected GitHub account with access to internal repositories.

The researchers proved the attack by asking an employee’s Codex account to open a harmless pull request. They stopped testing afterward and reported the flaws.

OpenAI fixed its side within 14 hours, while Discourse patched the image-processing issue and added stronger sandboxing. Hacktron received a $6,500 bug bounty.

Claude’s speed was the biggest warning. Claude Opus 4.8 struggled with the exploit, while Claude Opus 5 built an ARM64 version within three hours and later adapted it for Discourse.

Skilled researchers still guided the work, but Claude reduced a highly complex attack from months to days. Old software bugs are about to become much easier and cheaper to exploit.

PRESENTED BY TIGERDATA

Store It. Search It. Analyze It. One Postgres

Your AI app generates three kinds of data at once: events, vector embeddings, and the analytics you run on top of them. The default move is three systems, three sets of tooling, and pipelines to keep them in sync.

TimescaleDB handles all three in the Postgres you already run.

Hypertables ingest events at scale. pgvector and pgvectorscale store and search embeddings. Continuous aggregates keep analytics live without re-querying everything.

Same SQL, same tools, one system to operate. No pipelines to sync, no drift, no second database to feed.

Point it at your heaviest workload and watch it stay fast as data grows. It's still Postgres. Start on Tiger Cloud and get $1000 in credits.

EVERYTHING YOU NEED TO WIN WITH AI

1. FREE: 100x Cheaper Than Claude? JEV is One of the Ridiculously Cheapest AI Right Now. JEV takes a very different approach: dramatically lower API costs, predictable outputs, and a system designed to keep generated code grounded. So it can't hallucinate.

2. I Turned GPT-6 Astra Into My Ultimate AI OS. Here’s How to Build Your Own AI Second Brain. I connected it with Codex, gave it persistent business context, rules, memory, and reusable workflows, then turned the whole setup into an AI Second Brain that actually knows how I work.

3. There’s a New $1M AI Job Nobody Taught You in School with AI Agents and Automation. A new kind of marketer is emerging, and the job looks very different from running campaigns manually. It is becoming one of the most interesting roles in the AI era.

4. Copy 5 ChatGPT Work Agents Here & Let Them Handle All Your Recurring Work for You. They run your repetitive work almost on autopilot: research content, organize incoming information, prepare drafts, and keep ongoing workflows. I’ll give you the exact setups.

TODAY IN AI

AI HIGHLIGHTS

🧠 OpenAI released six reports showing models rewriting instructions, hiding mistakes, using leaked credentials, and sharing files without permission. New rules aim to make similar incidents public within 6–12 business days.

👨‍💻 Anthropic redesigned Claude Projects to manage complex work across several Claude Code sessions. Claude can delegate tasks, run tests, open PRs, share memory, and keep working after you log off.

⚖️ OpenAI launched Astra for Law, combining GPT‑6 Astra with a legal search index covering 230M+ URLs. It scored 54% on a legal research test, versus 38.7% for GPT‑6 Astra with normal web search.

🧬 Liquid AI and Insilico Medicine released two small models that analyze blood proteins, DNA markers, and other aging data. Despite having only 1.2B and 2.6B parameters, they beat GPT‑5, Gemini, and Claude on several longevity tasks.

🕵️ Google confirmed Gemini accidentally hacked three real companies during a cybersecurity test. Gemini guessed one password and found two leaked credentials, then stopped after realizing the systems weren’t part of the simulation.

💰 Daily AI Fundraising: Vantora, formerly UP.Labs, raised $100M from Silversmith Capital Partners to build startups for giants like Porsche, Alaska Airlines, and J.B. Hunt. It’s now focused on physical AI, helping industrial firms add autonomy to machines and own the technology behind it.

HOT PAPERS OF THE WEEK

1/ LimiX-2 brings foundation-model thinking to spreadsheets and tables
Researchers from Stable AI and Tsinghua University introduce LimiX-2, a model built to understand structured data such as spreadsheets, business tables, and scientific datasets. It beats other tabular foundation models across TabArena, TALENT, and BCCO, while also learning some causal relationships between features. What it means: AI could eventually analyze structured business data with far less custom model training.

2/ Atria Dawn shows how AI agents are becoming research partners
The Atria Team introduces Atria Dawn Preview, a 744B-parameter agentic model built for scientific research, engineering, and digital work. It achieves the highest reported score on 5 of 16 benchmarks, while its development study found that researchers considered about one-third of completed AI-assisted tasks infeasible without AI. Big shift: AI agents are moving beyond helping with small tasks and starting to participate in full research projects.

3/ Vidu S2 brings real-time AI video closer to live interaction
Researchers from Tsinghua University and Shengshu Technology, including Jun Zhu, introduce Vidu S2, which can generate and edit 720p video in real time at 25–42 FPS. Users can change characters, clothing, backgrounds, or visual styles while the video is still running, with support for spatial video and VR. What it means: AI video could become interactive like a live game or video call instead of something you generate and wait to watch.

NEW EMPOWERED AI TOOLS

  1. 🤝 Widgo is an AI sales rep for your website that answers visitors, identifies companies, scores buying intent, and books demos in 100+ languages.

  2. 🎯 Anysite.io lets Claude, Codex, Cursor, and other agents build B2B lead lists with company data, job titles, and emails through MCP or API.

  3. 💬 Switch brings AI agents into Slack, Teams, Discord, and Telegram, where they share channel context, history, and rules with your team.

  4. 🏭 Mastra Factory is an open-source software delivery workspace where AI agents handle planning, coding, implementation, and pull request reviews.

AI BREAKTHROUGH

gpt-6-astra-cracked-an-85-year-old-nazi-code

A German Army Enigma message from 1941 remained unsolved for 85 years. Researcher Carter Leffen recovered it with OpenAI’s GPT-6 Astra after roughly 10 hours and 14.8M key checks.

The breakthrough started with a human clue. Leffen borrowed ROSENOWROSENOW from a related message, which gave Astra a smaller search space.

GPT-6 Astra then:

  • Searched historical archives

  • Built an Enigma simulator

  • Wrote and ran cryptanalysis code

  • Recovered rotor order II-V-III and 10 plugboard pairs

The final message simply asked for a route of march and an immediate radio reply. Two independent programs reproduced the same 82-letter result, confirming the key. The full case study is publicly available.

The real breakthrough is the workflow. Carter supplied the judgment and direction, while Astra handled the research, coding, millions of tests, and verification. This is what serious agentic research now looks like.

We read your emails, comments, and poll replies daily

How would you rate today’s newsletter?

Your feedback helps us create the best newsletter possible

Login or Subscribe to participate in polls.

Hit reply and say Hello – we'd love to hear from you!
Like what you're reading? Forward it to friends, and they can sign up here.

Cheers,
The AI Fire Team

Reply

or to participate.