{"slug": "hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s", "title": "Hackers Used Anthropic's Claude to Break Into OpenAI. They Reached the ChatGPT Maker's Private Code.", "summary": "Security researchers at cybersecurity firm Hacktron AI used Anthropic's Claude Opus 5 to exploit a vulnerability in OpenAI's Discourse-powered community forum, gaining access to an OpenAI employee's ChatGPT account and reaching the company's internal GitHub environment, including a private repository known as \"Monorepo,\" according to The Wall Street Journal. OpenAI paid the team a $6,500 bug bounty, fixed the vulnerabilities, and revoked affected authentication tokens and sessions; the operation began July 23 and took less than 72 hours, with Claude Opus 5 succeeding after Claude Opus 4.8 failed to produce a working exploit. Hacktron Chief Technology Officer Mohan Pedhapati told the Journal, \"We're just three guys with Claude and Codex subscriptions,\" and OpenAI President and co-founder Greg Brockman said the company reassigned roughly 25% of its production engineers to security work following recent incidents.", "body_md": "# Hackers Used Anthropic’s Claude to Break Into OpenAI. They Reached the ChatGPT Maker’s Private Code.\n\n## The attack, was conducted by researchers at cybersecurity firm Hacktron AI as part of security testing.\n\nSecurity researchers used Anthropic's Claude to break into [OpenAI](https://www.ibtimes.com/topic/openai) systems and reach the ChatGPT maker's private software repositories, illustrating how quickly advanced [artificial intelligence](https://www.ibtimes.com/topic/ai) is changing the [cybersecurity](https://www.ibtimes.com/topic/cybersecurity) landscape.\n\nThe attack, [first reported by The Wall Street Journal](https://www.wsj.com/tech/ai/hackers-used-anthropics-claude-to-break-into-openai-b40ba883?mod=hp_lead_pos3), was conducted by researchers at cybersecurity firm Hacktron AI as part of security testing. OpenAI ultimately paid the team a $6,500 bug bounty after the researchers disclosed the vulnerabilities.\n\nThe researchers were able to gain access to an OpenAI employee's ChatGPT account and eventually reach the company's internal GitHub environment. OpenAI said the vulnerabilities have since been fixed and affected authentication tokens and sessions were revoked.\n\nThe operation began July 23, when Hacktron researchers discovered a vulnerability connected to Discourse, the third-party software that powers OpenAI's community forum. They were using a cybersecurity-focused version of Anthropic's Claude Opus 4.8 and asked the model to help develop code capable of exploiting the vulnerability.\n\nInitially, Claude couldn't produce a working exploit, but Anthropic released Claude Opus 5 that evening, and the newer model succeeded where its predecessor had failed, according to the researchers. The entire operation took less than 72 hours.\n\nThe exploit allowed the researchers to reach the Discourse server and obtain authentication tokens. More consequentially, some of those tokens belonged to OpenAI employees and were also valid for ChatGPT.\n\nThe researchers also discovered that the compromised accounts could potentially connect to OpenAI's GitHub environment, including a private repository known as \"Monorepo.\" People familiar with OpenAI's architecture described it to the Journal as a major repository containing proprietary software used to make the company's AI systems faster and more efficient.\n\nThe episode is striking because the researchers were not a massive intelligence operation or a state-backed hacking group. \"We're just three guys with Claude and Codex subscriptions,\" Hacktron Chief Technology Officer Mohan Pedhapati told the Journal.\n\nAI coding agents are beginning to automate parts of vulnerability discovery and exploit development that traditionally required highly specialized human expertise. Hacktron's work suggests that increasingly capable models could dramatically lower the cost and time required to conduct sophisticated attacks.\n\nThe breach also arrived during a particularly sensitive period for the AI industry. OpenAI recently disclosed six incidents involving concerning behavior by its own models and introduced new procedures for tracking and reporting such events.\n\nOpenAI has also intensified its defenses. President and co-founder Greg Brockman said the company reassigned roughly 25% of its production engineers to security work following recent incidents, according to the Journal.\n\n© Copyright IBTimes 2026. All rights reserved.", "url": "https://wpnews.pro/news/hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s", "canonical_source": "https://www.ibtimes.com/hackers-used-anthropics-claude-break-openai-they-reached-chatgpt-makers-private-code-3807619", "published_at": "2026-09-18 18:33:21+00:00", "updated_at": "2026-09-18 18:54:34.260085+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "large-language-models", "ai-agents"], "entities": ["Anthropic", "Claude", "Claude Opus 5", "Claude Opus 4.8", "OpenAI", "Hacktron AI", "Mohan Pedhapati", "Greg Brockman"], "alternates": {"html": "https://wpnews.pro/news/hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s", "markdown": "https://wpnews.pro/news/hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s.md", "text": "https://wpnews.pro/news/hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s.txt", "jsonld": "https://wpnews.pro/news/hackers-used-anthropic-s-claude-to-break-into-openai-they-reached-the-chatgpt-s.jsonld"}}