OpenAI Hacked by Researchers Using Claude
- Security startup Hacktron disclosed this week that it used Anthropic's Claude Opus 5 to compromise an OpenAI employee's ChatGPT account by exploiting a vulnerability in the company's community forum.
- Researchers discovered a heap buffer overflow in the forum's libheif image-processing software, which they developed into a functional exploit chain using Claude Opus 5 in less than 72 hours, according to Hacktron.
- After gaining forum access, the team exploited an identity flaw to compromise an employee's Codex account, then used it to generate a benign pull request within OpenAI's internal GitHub repository.
- OpenAI patched the community forum, revoked affected sessions, and paid Hacktron a $6,500 bounty, though the company has not published a detailed account of the incident.
- CEO Zayne Zhang of Hacktron noted that "the worlds of AI safety and cybersecurity are converging," highlighting how AI agents with broad credential access create new attack surfaces across internal infrastructure.
206 Articles
206 Articles
Researchers gained access to an OpenAI employee's ChatGPT account, allowing them to read internal messages. According to the report, the cybersecurity team discovered a vulnerability in OpenAI's system using a specialized security tool from Anthropic. This investigation was conducted as part of a bug bounty program. The company paid the researchers $6,500. The incident has raised new concerns about the security of AI models.
Researchers Used Claude to Exploit OpenAI Employee ChatGPT Accounts
Security researchers used Anthropic’s Claude AI models while investigating vulnerabilities that ultimately allowed them to take control of several OpenAI employees’ ChatGPT accounts, highlighting how advanced AI tools are changing the speed and scale of cybersecurity research. The three researchers, from security firm Hacktron, chained together two vulnerabilities and demonstrated that compromised access could extend [...]
A route into OpenAI's internal code was worth $6,500
Three researchers at Hacktron AI used Anthropic’s Claude to chain two weaknesses and reach OpenAI employee accounts and an internal code repository, in under 72 hours. They disclosed privately, OpenAI patched the single sign-on flaw in about 14 hours, and the team was paid $6,500. Neither weakness was an AI vulnerability, and the research paper […] This story continues at The Next Web
A cybersecurity team that discovered a vulnerability in a system used by the AI company OpenAI was found to have gained access to some of the company's internal systems using Anthropic's Claude software.
OpenAI hack: 3 Indian-origin researchers used Anthropic’s Claude to breach systems
Cybersecurity researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, gaining access to employee ChatGPT accounts and reaching the company’s internal software environment before reporting the flaws.
Claude Cracks OpenAI: How a Rival Model and Three Researchers Exposed Forum Flaws in Under 72 Hours
Three researchers from Hacktron AI used Anthropic’s Claude Opus 5 to chain a libheif vulnerability in OpenAI’s Discourse forum with SSO flaws, gaining employee ChatGPT access and reaching an internal GitHub repository called Monorepo. They proved control with a harmless pull request and earned a $6,500 bounty. The entire chain took under 72 hours.
Coverage Details
Bias Distribution
- 40% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




































