{"slug": "researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big", "title": "Researchers use Claude to breach OpenAI's internal systems, exposing big vulnerability", "summary": "Security research firm Hacktron said it breached OpenAI's internal systems by exploiting a flaw in OpenAI's public help forum, run on the Discourse platform, and reported the vulnerability to OpenAI and Discourse. OpenAI confirmed the flaw was fixed within about 14 hours of notification and paid the researchers a $6,500 reward, with OpenAI spokesperson Drew Pusateri saying the company narrowed permissions on Community sign-in tokens and revoked affected tokens and sessions. Hacktron said it initially used Anthropic's Claude Opus 4.8 to identify and exploit the flaw but struggled to make it work consistently, and that after Anthropic released Claude Opus 5 the newer model produced a working hack within about three hours; the researchers did not use the restricted Claude Mythos model.", "body_md": "## Researchers use Claude to breach OpenAI's internal systems, exposing big vulnerability\n\nWashington DC - **A security research company said Friday it managed to break into** [OpenAI](https://www.tag24.com/en/tech/artificial-intelligence)**'s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.**\n\nThe researchers from security firm Hacktron said they found a security flaw in OpenAI's public help forum, run by the Discourse platform, that allowed them to take control of the site.\n\n\"We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch,\" Hacktron said in a blog post.\n\n\"We appreciate their attention to detail and fast resolution of this issue,\" the post added.\n\nOpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a $6,500 reward.\n\n\"We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,\" said Drew Pusateri, an OpenAI spokesperson.\n\nThe Hacktron researchers said they initially used Anthropic's Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently.\n\nAfter Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours.\n\nThe hackers did not use Claude Mythos, [a more capable Anthropic model](https://www.tag24.com/en/tech/anthropic-says-us-government-has-lifted-restrictions-on-powerful-ai-models-3512415) that is restricted to a small group of vetted cyber-defense organizations.\n\n**Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built.**\n\n### Are AI tools making cyberattacks easier?\n\nHacktron said the underlying software flaw is not unique to OpenAI and is used across many companies' products, including those made by Slack and Meta.\n\nThe firm said it is continuing similar tests at other companies.\n\n**The case adds to growing concern among security experts that AI tools are making it faster and cheaper to** [carry out sophisticated cyberattacks](https://www.tag24.com/en/tech/hundreds-of-ai-agents-coordinated-hugging-face-cyberattack-as-report-reveals-more-details-3527633) **that once required specialized teams and months of work.**\n\nCover photo: IMAGO / ZUMA Press Wire", "url": "https://wpnews.pro/news/researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big", "canonical_source": "https://www.tag24.com/en/tech/artificial-intelligence/researchers-use-claude-to-breach-openais-internal-systems-exposing-big-vulnerability-3533403", "published_at": "2026-09-18 14:39:00+00:00", "updated_at": "2026-09-18 14:57:34.498611+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-products"], "entities": ["Hacktron", "OpenAI", "Anthropic", "Claude Opus 4.8", "Claude Opus 5", "Claude Mythos", "Discourse", "Drew Pusateri"], "alternates": {"html": "https://wpnews.pro/news/researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big", "markdown": "https://wpnews.pro/news/researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big.md", "text": "https://wpnews.pro/news/researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big.txt", "jsonld": "https://wpnews.pro/news/researchers-use-claude-to-breach-openai-s-internal-systems-exposing-big.jsonld"}}