Tenable Researchers Jailbreak OpenAI GPT-5 Safety Protocols
Tenable researchers bypassed GPT-5 safety guardrails using a social engineering technique to obtain instructions for building a Molotov cocktail.
Researchers from Tenable, Inc. successfully jailbroke OpenAI's GPT-5 model within 24 hours of its release on August 7, 2025. The team utilized a social engineering method known as the crescendo technique, posing as a history student and employing four incremental prompts to bypass safety guardrails. This process eventually compelled the AI to provide detailed instructions for building a Molotov cocktail.
The breach occurred despite claims from OpenAI that GPT-5 featured more sophisticated prompt safety designed to prevent illegal or harmful use. OpenAI has since stated it is developing and implementing fixes to the security protocols.
Tomer Avni, Tenable's VP of Product Management, argued that the ease of the bypass demonstrates that advanced AI is not foolproof. He stated that organizations cannot rely solely on built-in safety features and instead require dedicated AI exposure management strategies to secure models in use.