TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

Researchers Warn ChatGPT Crawler May Cause DDoS Attacks on Websites

Akinola Ajibola by Akinola Ajibola
January 22, 2025
in Artificial Intelligence, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email

In Brief
  • Security researchers discovered a flaw in ChatGPT‘s wrapper that might allow thousands of requests to be sent to a website, akin to a DDoS attack.
  • This also might allow attackers to execute DDoS assaults against unsuspecting firms.
  • OpenAI-owned ChatGPT may have a flaw that allows threat actors to perform distributed denial of service (DDoS) assaults on unwary targets.

Security researchers discovered a flaw in ChatGPT‘s wrapper that might allow thousands of requests to be sent to a website, akin to a DDoS attack. This also might allow attackers to execute DDoS assaults against unsuspecting firms.

OpenAI-owned ChatGPT may have a flaw that allows threat actors to perform distributed denial of service (DDoS) assaults on unwary targets.

According to information supplied by a cybersecurity researcher, OpenAI’s ChatGPT application programming interface (API) contains a vulnerability that can be used to launch a distributed denial of service (DDoS) assault against websites. The chatbot is said to be capable of sending thousands of network requests to a website using the ChatGPT crawler. The researcher believes that the vulnerability, which was assigned a high severity rating, is still active, with no word from the company on when it will be resolved.

German security researcher Benjamin Flesch discovered that the ChatGPT crawler, which OpenAI employs to collect data from the internet to develop ChatGPT, may be tricked into DDoSing arbitrary websites.

ChatGPT crawler can be triggered to DDoS a victim website via HTTP request to an unrelated ChatGPT API,” Flesch stated in a Github project containing a proof-of-concept. “This defect in OpenAI software will spawn a DDoS attack on the victim website, utilizing multiple Microsoft Azure IP address ranges on which ChatGPT crawler is running.” 

In a GitHub post published earlier this month, Germany-based security researcher Benjamin Flesch described the vulnerability in the ChatGPT API. The researcher also shared code for a proof-of-concept that makes 50 HTTP requests to a test website, demonstrating how the flaw may be leveraged to launch a DDoS attack.

According to Flesch, the vulnerability is discovered when handling HTTP POST requests to https://chatgpt.com/backend-api/attributions. It is a way for sending data to a server, which is commonly used by API endpoints to create new resources. When calling this function, the ChatGPT API expects a list of hyperlinks in the URL parameter.

Also worth reading
Dave Eggers Took His ChatGPT Warning Directly Inside OpenAI OpenAI Thinks the Future of ChatGPT Isn’t Typing, Its Talking AI Coding Is Creating A New Burden For Open-Source Maintainers Paystack’s AI Checkout Experiment Could Change How Nigerians Pay Online Apple’s OpenAI Lawsuit Turns The AI Hardware Race Into A Legal Fight Sam Altman And Elon Musk Are Now Fighting Over Space Data Centres

Flesch stated that the finding was made in January 2025 and has since been brought to the attention of both OpenAI and Microsoft, neither of which has acknowledged the flaw’s existence.  

According to the researcher, an apparent vulnerability in OpenAI’s API is that it does not check whether a hyperlink to the same page appears numerous times in the list. Because hyperlinks to a website might be written in many ways, the crawler makes multiple simultaneous network queries to the same domain. Furthermore, Flesch argues that OpenAI does not impose a limit on the number of hyperlinks that can be added to the URL parameter and transmitted in the same request.

As a result, a malicious actor may send thousands of hits to a website, quickly overwhelming its server. The security researcher assigned this vulnerability a high severity “8.6 CVSS” rating because it is network-based, has low execution complexity, requires no privileges or user interaction, and can have a significant impact on availability.

Flesch claimed to have notified OpenAI and Microsoft (whose servers host the ChatGPT API) about the issue several times via various channels after identifying it in January. He claimed to have reported it to the OpenAI security team, OpenAI workers through reports, the OpenAI data privacy officer, and Microsoft’s security and Azure network operations teams.

Security experts support Flesch’s view. Elad Schulman, founder and CEO of generative AI security firm Lasso Security Inc., told SiliconANGLE via email that “ChatGPT crawlers initiated via chatbots pose significant risks to businesses, including reputational damage, data exploitation, and resource depletion through attacks such as DDoS and denial of wallet.”

“Hackers targeting generative AI chatbots can exploit chatbots to drain a victim’s financial resources, especially in the absence of necessary guardrails,” Schulman pointed out. “By leveraging these techniques, hackers can easily spend a monthly budget of a large language model-based chatbot in just a day.”

Despite several attempts to flag the vulnerability, the researcher claims that it has not been resolved and that the AI firm has not acknowledged its existence. 

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • preview.11f9ddca
    Mastodon Announces DDoS Strike On Its Lead Server
  • 0_c_BDi0qfpXCm4Gon
    ChatGPT Service Disrupted After Significant Outage Today
  • bluesky1
    Bluesky Reviews The Outage Cause To Be A DDoS Attack
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • nitda-national-information-technology-development-agency
    NITDA Notifies Nigerians About ChatGPT Vulnerabilities
  • 0714_chatgpt
    Hackers Exploit ChatGPT to Distribute Malware
  • Palo-Alto-Networks-zero-day
    Critical Palo Alto PAN-OS Zero-Day Exploited in the…
  • Screenshot-513-e1718290879733-920x513
    Apple Password App Security Flaw Exposed Users to…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Artificial Intelligence Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: AIChatGPTddossecurity
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Meta Revenue Beats But AI Spending And Legal Costs Hit Profit July 29, 2026
  • Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer July 29, 2026
  • Russia Charges Telegram Founder Pavel Durov With Facilitating Terrorism July 29, 2026
  • Google DeepMind Reportedly Breaks Up The AlphaFold Team July 29, 2026
  • Huawei Pushes Enterprise AI Solutions In South Africa July 29, 2026
  • GoLemon Stops Taking Orders As Lagos Grocery Delivery Startup Winds Down July 29, 2026
  • Ethiopia Banking Summit Puts Digital Finance At The Centre Of Reform July 29, 2026
  • Clydestone Ghana Sues MTN Over Mobile Money IP Dispute July 29, 2026
  • DoorDash Launches DoorDash Air As It Builds Its Own Delivery Drones July 29, 2026
  • SK Hynix Posts Record AI Memory Profit But Shares Fall On High Expectations July 29, 2026
  • Cyera Buys Oasis Security For $1B As AI Agents Create New Identity Risks July 29, 2026
  • OpenAI Says Rogue Agent Also Breached Other Services After Hugging Face Incident July 29, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Subscribe

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.