3名黑客利用竞品Anthropic模型入侵OpenAI 这暴露了前沿AI实验室的哪些漏洞


2026年9月22日 美国东部时间下午2:53 / 哥伦比亚广播公司新闻

印度三名网络安全研究人员利用Anthropic的竞品AI模型成功入侵OpenAI系统,这一事件揭示了先进人工智能可能让企业自身及其用户面临攻击风险。

莫汉·佩达帕蒂是来自Hacktron公司的三名研究人员之一,他们曾突破OpenAI的防御。他表示,更先进的AI模型让像他这样的资深黑客工作起来轻松得多,也增加了犯罪分子效仿作案的风险。他将每一款新型AI模型称为“力量倍增器”,能够增强黑客的能力。

“随着模型迭代升级,它们在网络攻击方面的能力会变得非常强。”他说道。

在上周发布的一份报告中,Hacktron详细描述了他们在7月下旬如何利用Claude模型入侵OpenAI社区论坛用户的过程。该论坛是ChatGPT和OpenAI编码工具Codex的用户交流提问的平台,用户可以使用OpenAI账号登录。

Hacktron的研究人员最初使用Claude Opus 4.8寻找OpenAI社区论坛所使用的第三方服务Discourse的代码漏洞,并尝试利用该漏洞,但并未成功。然而就在当晚,更先进的Claude Opus 5模型正式发布。

次日,Hacktron团队就能够访问社区论坛上部分OpenAI用户的ChatGPT和Codex账号。这再次印证了AI开发的闪电速度——在这个案例中,仅一夜之间,AI的能力就发生了翻天覆地的变化。

Hacktron团队成功获取用户ChatGPT和Codex账号权限后,研究人员表示,他们本可以进一步访问这些账号关联的应用程序,包括电子邮件应用和Slack通讯工具。他们还能查看用户在ChatGPT上的所有对话内容。其中部分用户是OpenAI员工,他们的账号还关联了包括OpenAI内部邮箱在内的其他应用。

“你和ChatGPT聊天的所有内容——我们都可以泄露出去,都能获取到。”佩达帕蒂说道,“我能看到你和ChatGPT的所有对话,包括所有私人或私密内容。”

《华尔街日报》率先报道了Hacktron关于OpenAI的这份报告。

大型科技公司通常会推出“漏洞奖励计划”,即向外部安全研究人员——有时也被称为“道德黑客”——支付报酬,以奖励他们发现公司数字基础设施中的安全漏洞。发现漏洞、记录并提交给公司后,研究人员可能会获得数千美元,极少数情况下甚至能获得数百万美元的赏金。

OpenAI也曾推出多项漏洞奖励计划,Hacktron团队此次入侵正是在参与该计划。他们的初衷是帮助OpenAI找出安全漏洞,同时希望借此访问一款限制更少、能力更强的OpenAI网络模型。

“我们是正派阵营。”佩达帕蒂说道。

佩达帕蒂表示,如果没有Claude模型的帮助,他完成这类黑客攻击需要两到三个月的时间。
“这是我单打独斗、没有任何外援的情况。”他说,“但如果加上这些AI模型,整个情况就完全不一样了。”Hacktron团队完成整个黑客攻击仅用了不到三天时间。

自那以后,Anthropic和OpenAI都推出了更新的AI模型。佩达帕蒂估计,现在完成这类黑客攻击可能只需要不到一天的时间。他还透露,Hacktron的小型团队过去也曾入侵过苹果、谷歌、Facebook、Discord和微软Teams的系统。

佩达帕蒂担心,考虑到OpenAI的AI模型威力如此强大,该公司的安全防护并未达到应有的水平。
“你必须假设所有人都能入侵你的系统,然后基于这一点构建安全体系。按照目前的趋势来看,我认为很多AI实验室都没有做好这一点。”他说道,“OpenAI、Anthropic,我觉得他们只是在‘竞速跑’。”

Hacktron团队并非直接入侵OpenAI系统就能获取用户账号权限,他们只需找到OpenAI所使用的众多第三方服务中的一个漏洞即可。
“每家公司都有层层嵌套的依赖关系。你不需要在OpenAI的源代码中找到漏洞,只需要往下找一步即可。”佩达帕蒂说道,“攻击会逐层扩散,最终波及使用该服务的公司。”

在发给哥伦比亚广播公司新闻的一份声明中,OpenAI感谢了研究人员分享他们的发现。
“我们已经限制了社区登录令牌的权限,并撤销了受影响的令牌和会话。”OpenAI的一位发言人说道。

在Hugging Face遭到黑客攻击后,AI企业及其员工开始更公开地讨论强大AI给全社会带来的风险。
“和此前许多技术一样,AI也带来了风险,而且由于它是一项威力极强的技术,这些风险非常严峻。”Anthropic首席执行官达里奥·阿莫代伊近期在接受哥伦比亚广播公司新闻采访时说道。

其中一项风险是模型本身可能被盗,尤其是支撑模型强大能力的“权重参数”。多年来,研究人员一直担忧,即便开发强大内部模型的公司没有将其公开发布,外国敌对势力或犯罪分子仍有可能窃取这些模型。如果像Hacktron这样的小公司都能在几天内入侵OpenAI,那么敌对国家大概率也能做到,甚至可能更快。
“毫无疑问,这些AI实验室的技术与国家安全息息相关。美国政府和全球各国政府都已经证实了这一点。”安全与技术研究所的网络安全政策专家尼古拉斯·莱瑟森说道。

尽管近期一些AI领军人物承认有必要放缓AI开发速度,但多年来,加速前沿技术研发一直是OpenAI这类实验室的首要目标,莱瑟森表示。
“我们能心安理得地接受这种现状吗?我们作为一个社会,能接受当前的风险水平吗?因为目前正是由这些实验室来决定风险阈值,而我们已经看到了他们的选择。”

3 guys hacked OpenAI using a rival Anthropic model. Here’s what it shows about frontier labs’ vulnerabilities.

September 22, 2026 2:53 PM EDT / CBS News

Three cybersecurity researchers in India were able to hack OpenAI using a rival AI model from Anthropic, revealing that advanced artificial intelligence can put the companies themselves, and their users, at risk of attack.

Mohan Pedhapati, one of the three researchers from a company called Hacktron who broke into OpenAI, said that more advanced AI models allow veteran hackers like him to do their work much more easily — and raise the risks of criminals doing the same. He described each new model as “a force multiplier” that empowers hacking.

“As the models progress, they become very capable in cyber,” he said.

In a report published last week, Hacktron detailed how, in late July, they used Claude models to infiltrate users of OpenAI’s community forum. The forum is a space where users of ChatGPT and Codex, OpenAI’s coding agent, might go to ask questions about the products. Users can sign in with their OpenAI accounts.

The Hacktron researchers used Claude Opus 4.8 to find flaws in the code of a third-party service called Discourse, used for the OpenAI community forum. They tried to use Opus 4.8 to exploit the flaw, but were unsuccessful. However, that very same night, a more advanced model, Claude Opus 5, was released.

The next day, the Hacktron team could access the ChatGPT and Codex accounts of a subset of OpenAI users who were on the community forum. This was yet another reminder of the lightning speed of AI development — of how, in this case, literally overnight, capabilities can change in the AI world.

Once Hacktron had access to users’ ChatGPT and Codex accounts, the researchers said they also could have gained access to apps connected to these accounts, including email apps and Slack. They had the ability to see whatever conversations the users were having on ChatGPT. Some of those users included OpenAI employees, whose accounts were connected to other apps as well, like internal OpenAI email.

“Everything that you’re talking to ChatGPT [about] — we could leak it. We could get access to it,” Pedhapati said. “I can see whatever you’re talking to ChatGPT with. Like all the personal stuff or the private stuff.”

The Wall Street Journal first reported on Hacktron’s OpenAI report.

It’s common for big tech companies to offer “bug bounties.” These are payments made to outside security researchers — sometimes called “ethical hackers” — who discover security vulnerabilities in the larger company’s digital infrastructure. Find a flaw, document it and share it with the company, and you may get paid a bounty — thousands of dollars or, rarely, millions.

OpenAI has offered several bug bounties. This is what Hacktron was doing when it broke in. Their goal was to help OpenAI by pointing out gaps in their security, and then gain access to one of their more capable cyber models that have fewer guardrails.

“We are the good guys,” said Pedhapati.

Pedhapati said that it would have taken him two to three months to perform a hack like this without the help of Claude.

“That’s me doing it alone without any help,” he said. “But if you add these models, that changes the equation.” The entire hack took the Hacktron team less than three days.

Newer models from both Anthropic and OpenAI have been released since then, and Pedhapati estimates it could now take him less than a day to perform such a hack. Pedhapati and the small team at Hacktron have also hacked Apple, Google, Facebook, Discord and Microsoft Teams in the past, he said.

Pedhapati is worried that companies like OpenAI are not as secure as they need to be, considering how powerful their AI models are.

“You need to assume everyone can hack you, and then build your things based on that. On that trend, I think many of the labs are not doing it well,” he said. “OpenAI, Anthropic, they’re just, I think, speed running.”

The Hacktron team didn’t have to exploit OpenAI directly to gain access to its users’ accounts. They only had to find a flaw in one of the many third-party services used by OpenAI.

“Every company has a dependency that goes deep and deep. You don’t need to find a vulnerability in OpenAI source code itself, you can go one step down,” Pedhapati said. “It spirals up and comes back to the company that uses it.”

In a statement to CBS News, OpenAI thanked the researchers for sharing their findings.

“We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” an OpenAI spokesperson said.

AI companies and their employees, in the wake of the Hugging Face hack, are speaking more openly of concerns about society-wide risks of powerful AI.

“Like many technologies before it, AI brings risks, and because it is such a powerful technology, these risks are serious,” Anthropic CEO Dario Amodei recently told CBS News.

One of those risks is that the models themselves could be stolen, particularly the “weights” that help make these models so capable. For years, researchers have worried that even if companies developing powerful internal models don’t release them to the public, foreign adversaries or criminals could still steal them. If a small company like Hacktron can hack into OpenAI in a few days, an enemy state could likely do it as well, possibly even faster.

“I think unquestionably that the labs’ technology is national security relevant. We’ve seen that from the administration here and from governments across the world,” said Nicholas Leiserson, a cybersecurity policy expert at the Institute for Security and Technology.

Despite some recent statements from AI leaders acknowledging a need to slow down development, pushing the frontier as fast as possible has, for years, been the priority for labs like OpenAI, Leiserson said.

“Is that a comfortable place for us to land? Is that somewhere that we as a society feel is the appropriate risk level? Because right now it is the labs who are making that determination, and we’ve seen where they’ve landed.”

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2