The attack, was conducted by researchers at cybersecurity firm Hacktron AI as part of security testing. #
Security researchers used Anthropic's Claude to break into OpenAI systems and reach the ChatGPT maker's private software repositories, illustrating how quickly advanced artificial intelligence is changing the cybersecurity landscape.
The attack, first reported by The Wall Street Journal, was conducted by researchers at cybersecurity firm Hacktron AI as part of security testing. OpenAI ultimately paid the team a $6,500 bug bounty after the researchers disclosed the vulnerabilities.
The researchers were able to gain access to an OpenAI employee's ChatGPT account and eventually reach the company's internal GitHub environment. OpenAI said the vulnerabilities have since been fixed and affected authentication tokens and sessions were revoked.
The operation began July 23, when Hacktron researchers discovered a vulnerability connected to Discourse, the third-party software that powers OpenAI's community forum. They were using a cybersecurity-focused version of Anthropic's Claude Opus 4.8 and asked the model to help develop code capable of exploiting the vulnerability.
Initially, Claude couldn't produce a working exploit, but Anthropic released Claude Opus 5 that evening, and the newer model succeeded where its predecessor had failed, according to the researchers. The entire operation took less than 72 hours.
The exploit allowed the researchers to reach the Discourse server and obtain authentication tokens. More consequentially, some of those tokens belonged to OpenAI employees and were also valid for ChatGPT.
The researchers also discovered that the compromised accounts could potentially connect to OpenAI's GitHub environment, including a private repository known as "Monorepo." People familiar with OpenAI's architecture described it to the Journal as a major repository containing proprietary software used to make the company's AI systems faster and more efficient.
The episode is striking because the researchers were not a massive intelligence operation or a state-backed hacking group. "We're just three guys with Claude and Codex subscriptions," Hacktron Chief Technology Officer Mohan Pedhapati told the Journal.
AI coding agents are beginning to automate parts of vulnerability discovery and exploit development that traditionally required highly specialized human expertise. Hacktron's work suggests that increasingly capable models could dramatically lower the cost and time required to conduct sophisticated attacks.
The breach also arrived during a particularly sensitive period for the AI industry. OpenAI recently disclosed six incidents involving concerning behavior by its own models and introduced new procedures for tracking and reporting such events.
OpenAI has also intensified its defenses. President and co-founder Greg Brockman said the company reassigned roughly 25% of its production engineers to security work following recent incidents, according to the Journal.
© Copyright IBTimes 2026. All rights reserved.