AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
Brief
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO.
Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s own help forum.
The forum runs on Discourse, and until recently anyone logging in there through “Sign in with OpenAI” could, in theory, have had their ChatGPT and Codex accounts hijacked. Since staff connects all sorts of services to those accounts, GitHub, Slack, email, the actual blast radius was enormous. The whole thing, from first finding the bug to sitting inside an internal OpenAI repository, took less than 72 hours.
Here’s how the attack worked.
