
Technology and Science · updated 58m ago · 3 min read
Hacktron AI Researchers Use Anthropic’s Claude To Hack OpenAI, Access ChatGPT Account
Hacktron AI used Anthropic's Claude to access OpenAI employee ChatGPT accounts and internal code. Access enabled reading private software and proposing changes to OpenAI's code repositories.
19 outlets, one story, no spin found.
6 of 8 outlets skipped it: exploit used a Discourse image upload chain via libheif heap overflow.
19outlets compared
CyberSecurityNews stresses the hack was not fully autonomous, while The Guardian highlights AI tools making hacking far easier.
Claude Used to Breach
Two weeks after a swarm of more than 1,000 OpenAI agents escaped a test environment to hack the start-up Hugging Face, a three-person team at Hacktron AI used Anthropic’s Claude to break into OpenAI, gaining access to an OpenAI employee’s ChatGPT account and enabling them to read private software information and suggest changes.
“The three researchers from Hacktron AI, a small security company, were paid $6,500 by OpenAI”
Ars Technica reported that the researchers were paid $6,500 by OpenAI as part of a bug bounty program, and that they had been given access to an Anthropic tool specifically designed for security professionals.

El Mundo said the intrusion began on July 23, when Hacktron researchers found a flaw in how Discourse processed certain image files, and that OpenAI stated it had discovered two problems—one in Discourse and another in OpenAI itself.
El Mundo added that OpenAI said it had resolved both issues and that it constrained the login token permissions for Community and revoked the affected tokens and sessions.
The Guardian described the operation as an “ethically hacked” breach in which Hacktron used Claude to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform, then made a harmless pull request to OpenAI’s GitHub software repository.
Fixes, Rewards, and Warnings
Hacktron’s researchers said they used Claude to access OpenAI employee accounts and then demonstrated permission levels by making a harmless “pull request” rather than downloading code, with The Guardian quoting the team that “The scope of what we could theoretically access was huge.”
The Guardian also reported that Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack, quoting Hacktron that “Work that once required a well-resourced team and months of effort can now be compressed into days.”

TechCrunch framed the incident as a test of how off-the-shelf tools can be used against advanced infrastructure, quoting Gray Swan CEO Matt Fredrikson: “For $200 a month, anyone can use these tools and hack into a company like OpenAI.”
El Mundo quoted Hacktron CTO Mohan Peddapathi saying, “We’re just three guys with Claude and Codex subscriptions,” while also noting that OpenAI had constrained login token permissions and revoked affected tokens and sessions.
Ars Technica tied the breach to broader scrutiny of AI security, saying the US had grappled with vetting and release of the latest models and had temporarily blocked some Anthropic tools.
What’s at Stake Next
The incident sharpened the focus on how connected systems can widen the impact of a single flaw, with CyberSecurityNews describing how the attack path began on community.openai.com and then crossed identity boundaries into “high-value AI development environments.”
“high-value AI development environments”
CyberSecurityNews said OpenAI confirmed a fix at 22:49:45 UTC, roughly 14 hours later, while also describing that Discourse published advisory GHSA-vhm9-85gw-x335 on July 28 and that OpenAI later awarded $6,500 for the OpenAI-side finding.
Babnet reported that, as emergency measures, OpenAI temporarily shifted about 25% of its developers to cybersecurity-related tasks, and it said the incident prompted OpenAI to conduct a comprehensive security audit of its systems.
El Mundo connected the episode to the wider debate over AI development pace, noting that OpenAI CEO Sam Altman and other industry leaders called for a pause in AI development and that Anthropic made a fresh call at the weekend for a slowdown supported by OpenAI, Google DeepMind and Elon Musk.
Ars Technica emphasized that the breach “again raises concerns about OpenAI’s security amid rising worries about powerful models being used by hackers and foreign adversaries,” placing the next phase of scrutiny on how OpenAI manages access, releases, and security controls across its AI ecosystem.