Security researchers hacked OpenAI with the help of Anthropic's Claude
An experiment with foreign AI technology revealed how deep vulnerabilities in OpenAI's systems could run.
US security researchers hacked OpenAI as part of an authorized test, relying on the chatbot Claude from competitor Anthropic.
According to the researchers, the scope of what would theoretically have been accessible was substantial. The test took place with OpenAI's approval and falls into the category of so-called ethical hacking, in which vulnerabilities are deliberately uncovered to close them before third parties can exploit them.
How ethical hacking works
In so-called penetration testing, companies commission external specialists to attack their own systems. The goal is to find gaps before real attackers do. In this specific case, the researchers used Claude, the AI model from Anthropic, as a tool to identify vulnerabilities in OpenAI's infrastructure.
The fact that the technology of a direct competitor was used to uncover security gaps shows how the boundaries between major AI providers blur in practice.
Both companies develop language models trained on massive data centers with thousands of graphics processors, and both rely on robust security architectures to protect customer data, training data, and model weights.
What is at stake
According to OpenAI, it processes requests from hundreds of millions of users daily through products like ChatGPT. A successful attack on the underlying infrastructure could theoretically provide access to sensitive systems, internal model data, or user information. The researchers emphasized that the potential access scope they could have reached during the test was significantly larger than originally assumed.
Such tests have been established in the software industry for decades, but are taking on a new dimension in the field of artificial intelligence. AI systems process not only classical data, but also training material, model architectures, and in some cases proprietary algorithms, whose value is difficult to map in classical IT security categories.
Competition and cooperation at the same time
OpenAI and Anthropic are in fierce competition for market share, investor funds, and technological leadership in generative AI.
Anthropic was founded in 2021 by former OpenAI employees and has since received billions in investments from Amazon and Google, among others. The fact that Claude now helped as a tool to uncover vulnerabilities at OpenAI shows that technical security issues can be addressed independently of market rivalries.
The episode fits into a broader development in which cybersecurity is becoming a central issue for the entire AI industry. The more companies and government agencies rely on language models for sensitive tasks, the more attractive these systems become as attack targets for state actors, criminals, or competitors.
For European users and companies, the security of AI infrastructure is directly relevant, as many domestic firms and government agencies use services from OpenAI and Anthropic through cloud partners like Microsoft Azure or Amazon Web Services.
Austrian companies that have integrated ChatGPT or Claude into business processes are indirectly dependent on the security architecture of these providers. The EU AI Regulation, which will gradually come into force from 2025, requires providers of so-called high-risk AI systems to implement documented security measures, which gives tests like the one described increasing regulatory significance.
Source: theguardian.com | Original Article