Apple Sues OpenAI After Ex-Engineer’s ‘LOL’ Bug Exploit
Curated by the Inblix editorial team
Apple is throwing the book at OpenAI, demanding stiff penalties after stumbling on what it calls a “rare” authentication bug that let a departed engineer keep raiding confidential servers for weeks. The lawsuit, filed Friday, paints a picture not just of a technical glitch, but of a calculated talent raid designed to fast-track OpenAI’s hardware ambitions.
The engineer at the center of the storm is Chang Liu, an eight-year Apple veteran who joined OpenAI in January 2026. Apple alleges that on February 9, Liu discovered he could still access shared network folders from his unreturned Apple-issued laptop. Rather than report the bug, Liu allegedly spent weeks downloading “dozens of Apple’s confidential hardware-related files,” including presentations on complex circuit boards that Apple claims would be “invaluable to anyone developing hardware.” Internal messages uncovered during the investigation show Liu bragging to a current Apple employee, Yu-Ting “Alyssa” Peng, writing “LOL… I found out I can access the [network storage], so funny.”
Apple’s complaint doesn’t frame this as a one-off act of snooping. The company alleges a broader conspiracy where OpenAI targeted former Apple staff to “take an unlawful shortcut” in launching a line of AI-powered devices that could rival the iPhone. The files Liu allegedly grabbed included unreleased product specs, engineering presentations, and proprietary project data—some “expressly labeled as confidential.” The timing is brutal for OpenAI, which is trying to pivot from software phenom to consumer hardware player, a space where Apple’s supply chain and design secrets are a treasure map.
There is a small mercy buried in a lawsuit footnote. Apple confirmed the bug was “quickly fixed” once Liu’s messages were found, and server logs suggest the exploit wasn’t widespread. “The few other users affected by this bug do not appear to have accessed or stolen Apple’s confidential information,” the filing states. Still, the reputational damage cuts deep. A company built on secrecy just had its trust betrayed by someone who apparently found the whole thing hilarious. The injunctions Apple is seeking would block OpenAI from using any of the allegedly stolen data, but proving what made it into a product roadmap is a legal minefield that could drag on for years.
💡 Key Takeaways
- Apple alleges a former engineer exploited an unknown authentication bug for weeks after joining OpenAI, downloading confidential hardware files including unreleased product specs and circuit board designs.
- Internal messages show the engineer, Chang Liu, mocked Apple’s security lapse rather than reporting it, writing “LOL… I found out I can access the [network storage], so funny” to a current Apple employee.
- Apple frames this as part of a larger conspiracy by OpenAI to poach talent and steal trade secrets in a bid to shortcut its own AI-powered consumer hardware development.
- Apple confirmed the bug was quickly patched and that server logs suggest no other affected users accessed or stole confidential data, limiting the breach to Liu’s alleged actions.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.