Brief IA

Perplexity Computer: Vulnerability Exploited to Access Claude Opus 4.6

🤖 Models & LLM·Tom Levy·

Perplexity Computer: Vulnerability Exploited to Access Claude Opus 4.6

Perplexity Computer: Vulnerability Exploited to Access Claude Opus 4.6
Key Takeaways
1Yousif Astarabadi exploited a vulnerability in Perplexity Computer to access Claude Opus 4.6 at no apparent cost.
2Perplexity clarified that billing is asynchronous, refuting the idea of free access.
3The exfiltrated access token could be used by malicious scripts, but Perplexity has not yet commented on this vulnerability.
💡Why it mattersThis vulnerability could expose users to security risks, compromising trust in Perplexity's infrastructure.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Exploitation of a Vulnerability by Yousif Astarabadi

Security researcher, Yousif Astarabadi, recently highlighted a vulnerability in the Perplexity Computer system. By modifying the .npmrc file, he was able to execute a script at the program's startup, allowing him to access Claude Opus 4.6 at no apparent cost. This discovery raised questions about the security of access to this advanced AI model.

Misunderstanding About Free Access

Astarabadi initially concluded that this access was free. However, Perplexity clarified that billing is actually asynchronous. They provided details on billing events to dispel misunderstandings. The real issue lies in the fact that the exfiltrated access token could be exploited by malicious scripts, a vulnerability that Perplexity has not yet officially commented on.

Reactions on Social Media

On the platform X, Astarabadi claimed to have gained unlimited access to Claude Opus 4.6 by exploiting the infrastructure of Perplexity Computer. While his technical demonstration is valid, his conclusions about free access require revision in light of Perplexity's explanations.

Publication and Impact

On March 12, 2026, Astarabadi, who leads a startup in San Francisco, published an article on X. This quickly caught the attention of communities interested in innovations in artificial intelligence. He claimed to have obtained unlimited access to Claude Opus 4.6, the most sophisticated model developed by Anthropic.

The Role of Perplexity Computer

The exploit relies on Perplexity Computer, a recently launched product that allows an AI agent to execute code in a secure environment, known as a sandbox. Astarabadi noticed that Claude Code required an API access key from Anthropic, which needed to be present in the execution environment. After several attempts, he managed to extract the token and use it without his credits appearing to decrease.

Technical Analysis of the Exploit

  • Astarabadi described having failed six times before successfully executing his exploit.
  • He modified the .npmrc file to run a script at the application's startup.
  • This script allowed him to read environment variables and exfiltrate the token.

Clarifications on Billing

Since billing is asynchronous, the apparent lack of decrease in credits does not mean there is no cost. Perplexity explained that the retrieved token is not a shared API key, but a token generated specifically for each user session.

Implications and Concerns

The conclusion that access would be "free and unlimited" is therefore incorrect. However, the exfiltration of the token did work, raising security concerns. The token could be used outside the sandbox, potentially exposing users to injection attacks. Astarabadi has warned about these risks, but Perplexity has not yet officially responded to these concerns.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.