10 Sources
[1]
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum
[2]
A route into OpenAI's internal code was worth $6,500
Three researchers at Hacktron AI used Anthropic's Claude to chain two weaknesses and reach OpenAI employee accounts and an internal code repository, in under 72 hours. They disclosed privately, OpenAI patched the single sign-on flaw in about 14 hours, and the team was paid $6,500. Neither weakness
[3]
Hackers who broke into OpenAI warn the AI industry has a security problem
SAN FRANCISCO -- Cybersecurity researchers who broke into ChatGPT maker OpenAI earlier this summer say the artificial intelligence industry is unprepared for the security risks created by the growing power of its own technology. Researchers from computer security start-up Hacktron got inside the
[4]
3 guys hacked OpenAI using a rival Anthropic model. Here's what it shows about frontier labs' vulnerabilities.
Shaun Raviv is a Tarbell Fellow, funded through the Tarbell Center for AI Journalism, a nonprofit devoted to supporting news coverage of artificial intelligence. Three cybersecurity researchers in India were able to hack OpenAI using a rival AI model from Anthropic, revealing that advanced
[5]
3 Indians breached OpenAI systems using Claude. What happened next?
Three Indian-origin cybersecurity researchers -- Harsh Jaiswal, Mohan Pedhapati and Rahul Maini -- used Anthropic's Claude AI to demonstrate a chain of vulnerabilities that gave them access to OpenAI employee accounts and an internal GitHub repository, according to a Wall Street Journal
[6]
3 Indian-origin researchers used Claude to breach OpenAI systems in 72 hours
Three Indian-origin cybersecurity researchers at Hacktron AI used Anthropic's Claude models while investigating vulnerabilities that ultimately gave them access to OpenAI employee accounts and a private GitHub environment, according to reports. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini said
[7]
Security Researchers Use Anthropic's Claude to Penetrate OpenAI's Private Software Cache | PYMNTS.com
The researchers from Hacktron AI reached the software by using Claude to gain access to an OpenAI employee's ChatGPT account. Once they saw that they could reach OpenAI's GitHub service, a software repository, the researchers stopped and reported their findings to OpenAI, because they didn't want
[8]
Three Indian Researchers Use Anthropic's Claude to Hack into OpenAI
The issue once again opens up the can of worms that proponents of a safety-first AI development plan and its opponents are battling currently in the United States Now, this one is for the future AI fables! Three Indian researchers - Harsh Jaiswal, Rahul Maini and Mohan Pedhapati - working for
[9]
OpenAI Shifts 25% of Production Engineers to Security After AI Breach Scare
OpenAI president and co-founder Greg Brockman revealed that the company moved 25% of its production engineers away from their regular projects and assigned them to security work. The move followed concerns over the growing ability of AI systems to identify and exploit vulnerabilities in software
[10]
OpenAI Breached by Researchers Using Anthropic Models; What We Know so Far
Researchers Used AI to Test OpenAI: A cybersecurity research team used Anthropic's AI tools to uncover vulnerabilities in OpenAI's systems. The researchers accessed an OpenAI employee's ChatGPT account and reached internal software through a chain involving a third-party forum and
Share
Copy Link
Three Hacktron researchers used Anthropic's Claude Opus 5 to chain two vulnerabilities and access OpenAI employee accounts and internal code repository in under 72 hours. OpenAI patched the single sign-on flaw within 14 hours and paid a $6,500 bug bounty, but the incident exposes how AI security risks are accelerating faster than defenses.
Three researchers at cybersecurity firm Hacktron—Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—demonstrated how Anthropic Claude could be weaponized to breach OpenAI's systems
1
. The team chained two security flaws to access OpenAI staff accounts and an internal code repository in under 72 hours, spending less than $3,000 on AI tokens5
. This AI-assisted cyberattack wasn't malicious—the researchers conducted responsible disclosure, reported findings to OpenAI, and received a $6,500 bug bounty2
. OpenAI confirmed the fix approximately 14 hours after notification1
. Yet the episode raises urgent questions about whether frontier labs have adequate technical guardrails to match their claims about transformative AI capabilities.
Source: Hacker News
The OpenAI breach began at community.openai.com, the company's public help forum running on third-party software Discourse
4
. Hacktron discovered that specially crafted HEIC and HEIF image files could exploit a vulnerability in libheif, the image-processing library used by Discourse1
. The flaw, tracked as CVE-2026-32882 and scored 8.8 out of 10, enabled remote code execution on the forum server1
. Upstream fixes existed in libheif 1.22.0 since May 2026, but Debian 12 distributions still shipped the vulnerable version 1.19.7 when researchers tested in July1
.Control of the forum server alone wouldn't have reached OpenAI's internal systems. The critical second vulnerability was a single sign-on flaw in OpenAI's identity architecture
2
. The forum offered a "Sign in with OpenAI" option—the same SSO that staff used elsewhere1
. Once researchers compromised the forum server, shared login credentials let them take over ChatGPT and Codex accounts of forum members who were OpenAI employees, without victims taking any action1
. Hacktron emphasized this was an OpenAI identity problem, not a Discourse flaw—any service using the same sign-on could have granted identical access1
.
Source: PYMNTS
The researchers initially tried Claude Opus 4.8, which struggled to build working exploits when standard memory defenses like ASLR were enabled
1
. Anthropic released Claude Opus 5 on the evening of July 24, and within hours the model produced functional exploit code1
. Pedhapati estimated the hack would have taken him two to three months working alone without AI assistance4
. "As the models progress, they become very capable in cyber," Pedhapati explained, describing each new model as "a force multiplier" empowering offensive security work4
.Opus 5 shipped with safeguards designed to prevent writing exploit code for real targets
1
. Hacktron circumvented these by pointing the model at their own test server, disguised as a capture-the-flag practice target, then running it in an automated loop1
. Still, they stressed the work wasn't hands-off—skilled human direction remained essential1
. Anthropic has reported that criminal and state-backed groups are already using Claude models for real intrusions beyond answering questions1
.When one employee's Codex link to OpenAI's GitHub opened, it triggered a single pull request in the internal code repository
1
. Hacktron deliberately limited their actions—they didn't read source code, merge or ship anything, or touch customer data1
. However, the potential reach was far larger. Because staff connects services to ChatGPT and Codex, the same access could theoretically have extended to GitHub, Slack, and email1
. "Everything that you're talking to ChatGPT [about]—we could leak it. We could get access to it," Pedhapati said, noting they could see whatever conversations users were having, including private discussions4
.OpenAI paid Hacktron $6,500, recognizing "the OpenAI-side finding, not the actions against Discourse," since testing the forum fell outside its bug bounty program
1
. That payment for access reaching employee accounts and an internal code repository at a company valued in the hundreds of billions appears disproportionate2
. This fits a documented pattern where Anthropic, Google, and Microsoft paid bounties on agent vulnerabilities without publishing flaws, in one case paying $100 on an issue rated above nine out of ten for severity2
. Bounty economics signal what an industry thinks a bug class is worth—on that measure, the signal remains weak2
.Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, called the incident a "warning shot"
3
. "If three responsible researchers armed with commercial AI tools could achieve this level of access in days, we have to assume well-resourced foreign intelligence services are pursuing the same targets continuously and certainly never tipping off the target," Cilluffo said3
.Related Stories
Pedhapati questioned whether OpenAI's security measures align with its stated concerns about AI risks. "If the people building these systems truly believe they are powerful enough to create nuclear-level risks, and they are talking about slowing down because of those risks, why is that work...done through ordinary SAAS products," he posted
3
. He argued that companies like OpenAI need to assume everyone can hack them and build accordingly, adding that "many of the labs are not doing it well" and are "speed running"4
.
Source: CBS
OpenAI President Greg Brockman revealed that after the July incident, the company redirected substantial engineering resources toward security. "We took 25 percent of our production engineers and said, 'Sorry, all your projects are on hold. You are now defending.' We found a number of serious issues, and we fixed them," Brockman said in a podcast with Andreessen Horowitz
3
.
Source: CXOToday
Sayash Kapoor and Arvind Narayanan published an essay on September 14 arguing for "a middle ground between the cybersecurity and AI safety communities"
2
. They describe incidents as fair to call misalignment and reject the view that applying thirty-year-old security methods alone will suffice2
. Their recommendations include sandboxing, least privilege, logging, tripwires, shutdown mechanisms, and real-time monitoring tested against offensive agents2
. They also call for liability, mandatory incident reporting including near misses, independent auditing, whistleblower protections, and safe harbors for safety research2
. Critically, they corrected their own earlier position, saying they are no longer confident the industry is on track to take basic control precautions2
.Summarized by
Navi
[2]
[3]
12 Sept 2026•Technology

28 Jul 2026•Technology

21 Jul 2026•Technology
