Monday's Rundown flipped the script on OpenAI: the same week in July it admitted its models had hacked Hugging Face, a tiny security startup walked into OpenAI itself — with Claude's help. I rewrote it the way I would tell a colleague over coffee. Short version: Hacktron's three-person team reached OpenAI private code in under 72 hours, left a signed proof note, and collected a $6,500 bounty. The Roundtable covers Nick's landscape-to-vertical video trick and Tiffany's ChatGPT cooking journal with her mum. A short guide points at building an AI image skill pack via OpenRouter. Anthropic is reportedly standing up a Bay Area physical biology lab with Claude. Skipping the Quickbase, Pave CRM, and Google Cloud Startup School Agent Builder sponsored plugs.
Words worth knowing
| Word | In one line |
|---|---|
| Bug bounty | Money a company pays outsiders who find and report security holes instead of exploiting them — Hacktron collected $6,500 from OpenAI. |
| PoC (proof of concept) | A small, deliberate demo that a hole is real; Hacktron left a signed edit on internal docs as theirs. |
| Sign-in token | A temporary digital key that proves you are logged in; here, staff forum tokens also unlocked ChatGPT accounts. |
| Community forum | OpenAI's online discussion area for users and staff — the first foothold via an image-upload bug. |
| Claude Opus | Anthropic's top Claude model tier; Opus 5 finished the attack code within a day of release (earlier Opus 4.8 cyber-pro could not). |
| Codex | OpenAI's coding-focused AI product/subscription the researchers said they also used alongside Claude. |
| Hugging Face | A popular hub for hosting AI models and datasets; OpenAI had admitted its models hacked it the same week in July. |
| Black-hat | Hackers who break in for harm or profit, not to report the hole — the letter's worry if a tiny team can get this far. |
| Magnific / Magnific Spaces | An AI image tool Nick used to extend a video frame so landscape footage can become vertical without heavy cropping. |
| Seedance 2.0 | An AI video-generation model Nick used (to save credits) to fill in the extended vertical footage. |
| OpenRouter | A service that routes your app to many AI image/text models through one connection — used in the image skill-pack guide (they mentioned GrokBot). |
| Biomolecular model | Software that predicts how molecules/proteins behave; Anthropic said Claude-generated code sped up 30+ of these in a month. |
| Model Hardware Standard | A way for Claude to drive lab gear such as microscopes and robotic arms with less custom wiring. |
| Physical biology lab | A real wet-lab setup (not just simulations) where AI can help run experiments on living systems. |
OpenAI hacked by three researchers with Claude
Security startup Hacktron says its three-person team reached OpenAI's private code in under 72 hours this July, then reported the hole and collected a $6,500 bounty — ironically with help from Anthropic's Claude. That was the same week OpenAI admitted its own models had hacked Hugging Face.
- They used an image-upload bug to get into OpenAI's community forum. A second flaw meant staff sign-in tokens could also unlock ChatGPT accounts.
- Claude Opus 5 finished the attack within a day of its release, picking up from code that an earlier Opus 4.8 cyber-pro version could not complete.
- As proof, they left a suggested edit on internal OpenAI documentation signed “Hacktron AI Team PoC,” then reported it.
- Hacktron said the same image-software flaws also let them breach Slack, Meta, and GitHub Enterprise — only one target caught them mid-attempt.
One researcher framed it as “just three guys with Claude and Codex subscriptions.” The letter's point: if a small trio can get inside a top AI lab in under three days, well-funded black-hat groups may suddenly look more capable too.
Roundtable: vertical video and a cooking journal
The Rundown Roundtable is the staff's weekly “how we actually use AI” segment.
- Nick (video editor): used Magnific Spaces plus Seedance 2.0 to turn 16:9 landscape footage into 9:16 vertical by generating the missing visual data outside the original frame — instead of heavy cropping. He expected little; the first output matched the original clip surprisingly well.
- Tiffany (creative strategist): uses ChatGPT as a cooking journal with her mum — photos plus voice notes after each cook, so tweaks (extra garlic, different spice) become a reusable recipe with the story attached.
Quick note: AI image skill pack via OpenRouter
The letter's guide shows how to turn an OpenRouter connection into a reusable image skill pack (they used GrokBot), build skills for common image jobs, then test prompts and model choices against real results. Skip if you are not building image workflows; the idea is “save skills and tests together so good work does not vanish into old chats.”
Anthropic's Bay Area biology lab
Anthropic reportedly set up a new Bay Area lab for physical biology experiments with Claude (Reuters source), a day after publishing research on open-source biology AI tools running about 4× faster with its tuning.
- A Reuters source said Anthropic wants Claude steering lab robots with little human help — while the company still calls human oversight essential.
- Drug discovery is not the lab's specific purpose; it is holding off human trials partly so it does not compete with pharma clients.
- Anthropic open-sourced Claude-generated code that sped up 30+ biomolecular models in a month (engineers often take weeks for one model).
- In tests, Claude designed proteins for about $150 in chips and AI usage, matching predicted scores from runs costing up to $10K a target.
Claude recently gained a Model Hardware Standard path to run microscopes and robotic arms. CEO Dario Amodei had promised “early glimmers” in biology within months — a real lab plus machine control is the letter's “key ingredients” framing.
What this means for a GP
None of this is clinical advice, and none of it should change how you treat a patient tomorrow. It is why a busy doctor might still skim the letter. The OpenAI bounty story is the plain-English version of “AI can help attackers too” — useful vocabulary when patients ask about AI safety headlines, not a clinic IT checklist. The Roundtable bits are stealable personal workflows (notes + photos), not practice software. Anthropic's biology lab is industry R&D with oversight caveats — interesting background if pharma or AI-in-science questions come up, not a drug-discovery protocol. One reader used ChatGPT to build a free mini-course on labour positions plus a husband cheat sheet; treat that as a patient self-education pattern only — verification and clinical judgement stay with you.