cd /news/ai-safety/security-researchers-hacked-openai-u… · home topics ai-safety article
[ARTICLE · art-133995] src=uk.pcmag.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Security Researchers Hacked OpenAI Using Anthropic's Claude

Security startup Hacktron used Anthropic's Claude Opus 5 to take over an OpenAI employee's ChatGPT account in July through a flaw in the third-party community forum platform Discourse, according to a Wall Street Journal report. The researchers, Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, reported the vulnerability to OpenAI and Discourse, which resolved it within 24 hours, and OpenAI paid Hacktron a $6,500 bug bounty. Hacktron said Claude Opus 5 produced a working exploit that Opus 4.8 could not, and Pedhapati wrote on X that "AI is reducing the amount of scarce expertise needed to develop exploits.

by read1 min views2 publishedSep 18, 2026
Security Researchers Hacked OpenAI Using Anthropic's Claude
Image: Uk (auto-discovered)

In July, independent security researchers used Anthropic’s Claude to hack OpenAI, the Wall Street Journal reported. The researchers, participating in OpenAI's bug-bounty program, were able to take over an OpenAI employee’s ChatGPT account, giving them unauthorized access to sensitive information and the ability to suggest changes within OpenAI’s software.

The breach was conducted by Hacktron, a security startup specializing in software vulnerability detection. The team confirmed that they could compromise employee ChatGPT accounts via a flaw in the third-party community forum platform Discourse. The researchers say they conducted the hack without viewing sensitive information or pushing malicious code in OpenAI’s internal systems.

Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini are the lead researchers on the investigation. “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum could have had their ChatGPT and Codex accounts taken over,” they wrote in a blog post breaking down the attack. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack, and emails.”

The researchers promptly reported their findings to OpenAI and Discourse, and collaborated with the companies to resolve the vulnerabilities within 24 hours. OpenAI reportedly paid Hacktron a $6,500 bug bounty following the investigation.

Hacktron claims that the breach took just a few days to execute, and was aided significantly by the release of Claude Opus 5, as the new model was able to produce a working exploit that Opus 4.8 could not. The OpenAI breach was part of a larger project called HEIF Heist, Hacktron’s investigation into attacks that exploit image decoders.

"AI is reducing the amount of scarce expertise needed to develop exploits," Pedhapati wrote on X. “Work that once took months can now take days.”

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/security-researchers…] indexed:0 read:1min 2026-09-18 ·