Hackers breached OpenAI, adding to fever pitch of security and safety concerns

A small group of cybersecurity researchers said Sunday that they broke into OpenAI earlier this year, an announcement that has added a new element of alarm around AI security and safety.The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts.
As is customary for researchers — sometimes called “white-hat hackers” — they caused no harm to the company’s systems.Hacktron conducted the entire operation within 72 hours in late July, soon after some of OpenAI’s agents broke containment and hacked the AI platform Hugging Face.An OpenAI spokesperson confirmed Hacktron’s report and said the vulnerabilities have since been patched.“We thank the researchers for contacting us and sharing their findings,” the spokesperson said.The news comes as concerns about AI safety have exploded into public view in recent weeks.
Safety researchers have resigned from major companies and issued stern warnings that the advanced technology could pose a risk to the human race, and politicians from across the political spectrum have called for action.While most of those concerns have centered on the capabilities of advanced AI models, the security of the companies themselves is also a significant issue.
AI development is extremely competitive, and concerns of theft — primarily through a process known as distillation — abound.Add to GoogleGov.
Shapiro calls for AI regulation without pausing development as safety concerns grow06:14Like many companies, OpenAI maintains a “bug bounty” program, which offers to pay cybersecurity researchers who find novel ways to hack it instead of selling them to malicious hackers who would do the company harm.Hacktron’s researchers wrote in their blog post that OpenAI paid them $6,500 for the discovery.
There is no evidence that any othe...