OpenAI has talked a big game about AI for cyberdefense. But when
@HacktronAI broke into their internal repository and reported it, they received a bug bounty of just $6,500 because one of the vectors for the attack was "out of scope".
This is atrocious.
If we actually want a flood of defenders auditing these systems, companies need to take bounties more seriously. Signing letters isn't enough.
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
Show more