top of page

Claude Wrote the Exploit That Hit OpenAI. Agencies, Lock Your Stack.

Writer: Aseem Singh
Aseem Singh
11 minutes ago
2 min read

Three researchers at Hacktron chained a heap overflow with a single sign-on flaw, reached OpenAI employee Codex accounts, and opened a pull request inside the internal monorepo. Opus 4.8 could not build the exploit. Claude Opus 5 did it in three hours.

That is the week we are in. Not 'AI writes better captions.' A frontier model wrote the lockpick.

What actually shipped this week

The rest of the feed is not quieter. OpenAI, Anthropic, and Google spent weeks coordinating on safety after Dario Amodei asked the industry to pace the frontier. A federal antitrust complaint in Northern California now argues those public statements look like competitors agreeing to slow down. Anthropic and Accenture separately said they will put about $2 billion into model evaluation as safety pressure rises.

Same week, OpenAI is talking about a valuation near $1.2 trillion and a cash-burn path that reports put near $280 billion by 2030. The labs want more compute, more evaluation, and more time. They also keep shipping models that can do damage faster than last month's version.

The marketing problem nobody wants on the brief

Here is where this stops being a safety-blog story and starts eating agency work. Marketing teams are handing agentic systems the same class of keys: ad accounts, CMS logins, brand folders, customer lists. IAB already had to add pricing-provenance fields to agentic ad protocols after buying agents started inventing bid prices. One connected-TV test blew a $25,000 budget by 5x.

Generative engine optimization is the other half. Searches for GEO are up hard. Estée Lauder just bought AI-search visibility across ChatGPT and Gemini so the model recommends the right product, not a hallucinated sibling SKU. If your brand is still optimizing only for blue links, you are arguing with last year's customer.

What we are changing at Dzine Prodigy this week:

  • No agent gets production ad-account write access without a daily token cap and a human kill switch.

  • Every client page that should be cited by ChatGPT, Gemini, or Perplexity gets a GEO pass: stats, named sources, clean product facts.

  • AI talent in ads gets labeled. California already made that a legal problem, not a taste problem.

  • We freeze the stack for 14 days. New models can wait. The brief cannot.

Do this before Friday

Pick one live campaign. Write down which model can touch it, what it is allowed to spend, and who signs the kill switch. If you cannot answer those three lines, you do not have an AI marketing stack. You have an unpaid intern with admin.

The model can write the exploit now. Your job is to make sure it never writes the media plan unsupervised.

Recent Posts

See All

Comments


bottom of page