4 Sources
[1]
ChatGPT Could Theoretically Carry Out DDoS Attacks in the Wrong Hands
You Can Now Set ChatGPT to Complete Tasks, and This Is How to Use It Properly As the world comes to terms with AI assistants, we're learning all the interesting things they can do, for better and for worse. One example that lands firmly in the latter camp is a theoretical attack that forces
[2]
Can ChatGPT be used for DDoS attacks? Researchers say yes
According to a report published by The Register, OpenAI's ChatGPT crawler is reportedly vulnerable to manipulation, allowing it to potentially initiate distributed denial of service (DDoS) attacks on arbitrary websites. This issue remains unacknowledged by the tech company. A write-up from
[3]
OpenAI's ChatGPT Crawler Can Be Used to DDoS Websites, Researcher Claims
The vulnerability was given a high severity rating by the researcher OpenAI's ChatGPT application programming interface (API) has a vulnerability that can be exploited to initiate a distributed denial of service (DDoS) attack on websites, according to details shared by a cybersecurity researcher.
[4]
ChatGPT crawler flaw opens door to DDoS, prompt injection
OpenAI's ChatGPT crawler appears to be willing to initiate distributed denial of service (DDoS) attacks on arbitrary websites, a reported vulnerability the tech giant has yet to acknowledge. In a write-up shared this month via Microsoft's GitHub, Benjamin Flesch, a security researcher in Germany,
Share
Copy Link
A security researcher has uncovered a vulnerability in ChatGPT's crawler that could potentially be exploited for DDoS attacks and prompt injection, raising concerns about AI security and OpenAI's response to the issue.

Security researcher Benjamin Flesch has uncovered a significant vulnerability in OpenAI's ChatGPT crawler that could potentially be exploited to launch Distributed Denial of Service (DDoS) attacks on websites
1
. The flaw, which Flesch describes as a "severe quality defect," lies in the handling of HTTP POST requests to a specific API endpoint used by ChatGPT2
.The vulnerability stems from ChatGPT's API not verifying if hyperlinks are repeated within a list or enforcing a limit on the total number of hyperlinks submitted
2
. This allows an attacker to send thousands of hyperlinks in a single HTTP request, potentially overwhelming a target website. The ChatGPT crawler, using Cloudflare, accesses the site from different IP addresses with each request, making it difficult for victims to trace the source of the attack2
.Flesch demonstrated that a single API request could be amplified into 20 to 5,000 or more requests to a chosen victim's website every second
4
. This amplification effect means an attacker can send a small number of requests to the ChatGPT API, resulting in a large number of requests to the victim's site2
.In addition to the DDoS potential, Flesch identified another issue related to prompt injection. This flaw allows the crawler to process arbitrary questions using the same attributions API endpoint, rather than only fetching website data as intended
2
4
.Flesch assigned the vulnerability a high severity rating of 8.6 CVSS, citing its network-based nature, low complexity in execution, and potential for high impact on availability
3
. He reported the issue through multiple channels, including OpenAI's BugCrowd platform and Microsoft's security teams, but claims to have received no response2
3
.Related Stories
Despite multiple attempts to flag the vulnerability, Flesch states that the issue remains unresolved, and OpenAI has not acknowledged its existence
3
. The Register reached out to OpenAI for comments but did not receive a reply4
.This vulnerability raises questions about the security practices in AI development. Flesch criticized OpenAI for failing to implement basic security measures, such as deduplicating URLs or limiting the size of URL lists
2
. He speculated that the API might be an experimental project for OpenAI's AI agents, lacking necessary validation logic to prevent abuse4
.Elad Schulman, founder and CEO of Lasso Security Inc., agreed with Flesch's conclusions and highlighted another potential exploit. He suggested that if a hacker compromised someone's OpenAI account, they could "easily spend a monthly budget of a large language model-based chatbot in just a day," potentially causing financial damage
1
.As AI continues to evolve, this incident underscores the need for companies to implement robust security measures to prevent the abuse of their services. It also highlights the importance of responsible disclosure and timely responses to reported vulnerabilities in the AI industry.
Summarized by
Navi
[4]
10 Oct 2024•Technology

08 Aug 2025•Technology

08 Jan 2026•Technology
