TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

Researchers Warn ChatGPT Crawler May Cause DDoS Attacks on Websites

Akinola Ajibola by Akinola Ajibola
January 22, 2025
in Artificial Intelligence, Security
Share on FacebookShare on Twitter

Security researchers discovered a flaw in ChatGPT‘s wrapper that might allow thousands of requests to be sent to a website, akin to a DDoS attack. This also might allow attackers to execute DDoS assaults against unsuspecting firms.

OpenAI-owned ChatGPT may have a flaw that allows threat actors to perform distributed denial of service (DDoS) assaults on unwary targets.

According to information supplied by a cybersecurity researcher, OpenAI’s ChatGPT application programming interface (API) contains a vulnerability that can be used to launch a distributed denial of service (DDoS) assault against websites. The chatbot is said to be capable of sending thousands of network requests to a website using the ChatGPT crawler. The researcher believes that the vulnerability, which was assigned a high severity rating, is still active, with no word from the company on when it will be resolved.

German security researcher Benjamin Flesch discovered that the ChatGPT crawler, which OpenAI employs to collect data from the internet to develop ChatGPT, may be tricked into DDoSing arbitrary websites.

ChatGPT crawler can be triggered to DDoS a victim website via HTTP request to an unrelated ChatGPT API,” Flesch stated in a Github project containing a proof-of-concept. “This defect in OpenAI software will spawn a DDoS attack on the victim website, utilizing multiple Microsoft Azure IP address ranges on which ChatGPT crawler is running.” 

In a GitHub post published earlier this month, Germany-based security researcher Benjamin Flesch described the vulnerability in the ChatGPT API. The researcher also shared code for a proof-of-concept that makes 50 HTTP requests to a test website, demonstrating how the flaw may be leveraged to launch a DDoS attack.

According to Flesch, the vulnerability is discovered when handling HTTP POST requests to https://chatgpt.com/backend-api/attributions. It is a way for sending data to a server, which is commonly used by API endpoints to create new resources. When calling this function, the ChatGPT API expects a list of hyperlinks in the URL parameter.

Flesch stated that the finding was made in January 2025 and has since been brought to the attention of both OpenAI and Microsoft, neither of which has acknowledged the flaw’s existence.  

According to the researcher, an apparent vulnerability in OpenAI’s API is that it does not check whether a hyperlink to the same page appears numerous times in the list. Because hyperlinks to a website might be written in many ways, the crawler makes multiple simultaneous network queries to the same domain. Furthermore, Flesch argues that OpenAI does not impose a limit on the number of hyperlinks that can be added to the URL parameter and transmitted in the same request.

As a result, a malicious actor may send thousands of hits to a website, quickly overwhelming its server. The security researcher assigned this vulnerability a high severity “8.6 CVSS” rating because it is network-based, has low execution complexity, requires no privileges or user interaction, and can have a significant impact on availability.

Flesch claimed to have notified OpenAI and Microsoft (whose servers host the ChatGPT API) about the issue several times via various channels after identifying it in January. He claimed to have reported it to the OpenAI security team, OpenAI workers through reports, the OpenAI data privacy officer, and Microsoft’s security and Azure network operations teams.

Security experts support Flesch’s view. Elad Schulman, founder and CEO of generative AI security firm Lasso Security Inc., told SiliconANGLE via email that “ChatGPT crawlers initiated via chatbots pose significant risks to businesses, including reputational damage, data exploitation, and resource depletion through attacks such as DDoS and denial of wallet.”

“Hackers targeting generative AI chatbots can exploit chatbots to drain a victim’s financial resources, especially in the absence of necessary guardrails,” Schulman pointed out. “By leveraging these techniques, hackers can easily spend a monthly budget of a large language model-based chatbot in just a day.”

Despite several attempts to flag the vulnerability, the researcher claims that it has not been resolved and that the AI firm has not acknowledged its existence. 

Related Posts:

  • preview.11f9ddca
    Mastodon Announces DDoS Strike On Its Lead Server
  • Outlook-search-Problem-after-Windows-10-security-patch-confirmed
    Microsoft Confirms June Outlook Outages Was A DDoS Attack
  • 0_c_BDi0qfpXCm4Gon
    ChatGPT Service Disrupted After Significant Outage Today
  • bluesky1
    Bluesky Reviews The Outage Cause To Be A DDoS Attack
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • nitda-national-information-technology-development-agency
    NITDA Notifies Nigerians About ChatGPT Vulnerabilities
  • 0714_chatgpt
    Hackers Exploit ChatGPT to Distribute Malware
  • Palo-Alto-Networks-zero-day
    Critical Palo Alto PAN-OS Zero-Day Exploited in the…

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: AIChatGPTddossecurity
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Anthropic Asked for AI Regulation, Fable 5 May Show What That Really Looks Like June 14, 2026
  • Amazon Raised Anthropic AI Security Concerns Before US Crackdown on Fable 5 and Mythos 5 June 14, 2026
  • Europe Calls Anthropic AI Ban a ‘Wake-Up Call’ as US Shuts Off Access to Fable 5 and Mythos 5 June 14, 2026
  • US Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Over National Security Concerns June 14, 2026
  • Elon Musk Hits $1.1 Trillion as SpaceX Surpasses $2 Trillion Valuation June 13, 2026
  • SpaceX Prices Record $75 Billion IPO as Elon Musk Nears Trillionaire Status June 12, 2026
  • DoorDash Launches AI Chatbot for Food Orders June 12, 2026
  • Pool Launches App That Makes Screenshots More Useful June 12, 2026
  • Deezer Launches Tool to Detect AI-Generated Music June 12, 2026
  • Coinbase Introduces Platform for Agents to Trade Assets and Buy Premium Insights June 12, 2026
  • Meta Expands Edits App With AI Features and Desktop Access June 12, 2026
  • Ready-made LMS and custom development. Pros and cons of each path. June 11, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.