Cybersecurity researchers who recently gained access to OpenAI's systems have issued a warning, indicating that the artificial intelligence (AI) sector is not yet prepared for the security risks generated by the advancement and growing power of the technology itself.
Researchers from Hacktron, a startup focused on computer security, managed to penetrate the systems of the company responsible for ChatGPT, with the help of Claude, a chatbot developed by Anthropic, OpenAI's main competitor.
According to Hacktron's publications on the X platform, the attack began by exploiting a public messaging panel, which allowed the researchers to access private OpenAI systems, including parts of the company's internal code.
OpenAI promptly corrected the security flaw and compensated the researchers with $6.5 thousand (equivalent to R$ 33.4 thousand) for discovering and reporting the vulnerability.
This incident, coupled with other cases where AI models accessed the internet undetected and attacked other corporations, has intensified criticism from cybersecurity experts. For these experts, the efforts of AI companies to protect their systems do not match the immense power they grant to the technology.
Criticism over system vulnerability
Mohan Pedhapati, one of the Hacktron researchers involved in the OpenAI attack, argued that the use of standard corporate software, such as Slack, consumer browsers, and other publicly accessible applications, makes the company susceptible to attacks. Pedhapati questioned in an X post: 'If the people who build these systems truly believe they are powerful enough to create nuclear-level risks, and they are talking about slowing down because of these risks, why is this work... done through common SaaS products?'
Sam Altman, CEO of OpenAI, joined other industry leaders advocating for a slowdown in AI development due to concerns that technological capabilities are progressing faster than the industry's ability to manage them.
In a statement, an OpenAI spokesperson thanked the researchers for reporting their findings and confirmed that the company's security measures have been reinforced.
Expert Warning
Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, considered the success of a small team of researchers in the attack—conducted at a cost of $3 thousand (R$ 15.4 thousand) to use Anthropic's systems—as a 'warning shot.' Cilluffo warned: 'If three responsible researchers, equipped with commercial AI tools, managed to achieve this level of access in a matter of days, we must assume that foreign intelligence services with many resources are continuously pursuing the same targets and certainly never notifying the target about what they did or how they did it.'
National security experts have been warning for years that American AI companies should expect to be targeted by hackers supported by foreign governments interested in diminishing U.S. technological leadership.
Calls to slow down AI development have also prompted lawmakers from both major American parties to advocate for stricter government oversight of the sector.
On the other hand, Donald Trump vehemently rejected these proposals, insisting that the industry must accelerate to maintain competitiveness against China.
The attack conducted by Hacktron occurred approximately at the same time as the episode involving AI agents.
Shortly after the incident, OpenAI reallocated a substantial portion of its engineering resources to strengthen security. Greg Brockman, the company's president, informed a podcast by Andreessen Horowitz that 25% of production engineers were temporarily assigned to this function. Brockman detailed: 'We took 25% of our production engineers and told them: 'Sorry, all your projects are suspended. Now you are in defense.'' He added that they found and fixed several serious issues.
OpenAI's Reaction to Researchers
The Hacktron researchers also criticized the way OpenAI responded after receiving notification of the vulnerability. Like many large corporations, OpenAI publicly promotes the disclosure of vulnerabilities by security researchers.
Fabian Faessler, head of agent engineering at Hacktron, stated in an X post that Dane Stuckey, OpenAI's Chief Information Security Officer, had called the researchers unprofessional, expressing his expectation for a more welcoming response from the company.
Dan Wallach, a resident AI security researcher at Rand, opined that OpenAI was lucky the vulnerability was discovered by researchers who chose to come forward and share their findings. Wallach commented to The Washington Post: 'As a general rule, it is not polite to do what they did, but I think OpenAI should be satisfied because the attacker was kind enough to notify them.'
Subsequently, following the publication of Faessler's series of posts on X, Stuckey contacted the researcher to apologize, as reported by Faessler in a subsequent post.

