cd /news/ai-safety/this-tiny-cybersecurity-startup-mana… · home topics ai-safety article
[ARTICLE · art-133428] src=businessinsider.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

This tiny cybersecurity startup managed to hack OpenAI using Claude, and won a $6,500 bounty

Hacktron, a San Francisco-based AI cybersecurity startup with fewer than 10 employees, discovered a vulnerability in OpenAI's community help forum sign-in that could have exposed ChatGPT and Codex accounts, then exploited it using Anthropic's Claude under Anthropic's Cyber Verification Program, according to a disclosure published Sunday. Hacktron CEO and cofounder Zayne Zhang said the team accessed an OpenAI employee's account and prompted the employee's Codex account to suggest changes in OpenAI's internal code repository, stopped there without accessing internal code, and reported the issue to OpenAI, earning a $6,500 bounty. An OpenAI spokesperson said the company "narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.

by read2 min views4 publishedSep 18, 2026
This tiny cybersecurity startup managed to hack OpenAI using Claude, and won a $6,500 bounty
Image: Businessinsider (auto-discovered)

A small AI startup used Claude to hack into OpenAI's internal codebase shortly after the OpenAI Hugging Face hack.

Zayne Zhang, the cofounder and CEO of Hacktron, told Business Insider that his research team has begun investigating security vulnerabilities at frontier AI companies like OpenAI to determine whether they have gaps that could be exploited by AI agents. Hacktron is a San Francisco-based AI cybersecurity startup.

In July, Zhang's team discovered some gaps in OpenAI's infrastructure. According to Hacktron's disclosure about the incident, published on Sunday, any user or OpenAI employee logging into OpenAI's community help forum could have had their ChatGPT and Codex accounts hacked.

Hacktron then tried to exploit that vulnerability via Claude. The company had access to Anthropic's Cyber Verification Program, which relaxed certain cyber restrictions on Claude for authorized security research, Zhang said.

The team managed to hack into an OpenAI employee's account and prompt the employee's Codex account to suggest changes in OpenAI's internal code repository. Hacktron said the team stopped there, didn't access any internal code, and flagged the issue to OpenAI.

Hacktron said in its disclosure that the company won a $6,500 bounty from its discovery. The startup was launched less than a year ago and has fewer than 10 employees.

An OpenAI spokesperson said in an emailed statement to Business Insider about Hacktron, "We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions."

"The worlds of AI safety and cybersecurity are converging, and we think that having more cybersecurity experts in the conversation is always a good thing for the industry," Zhang said of the incident,

Representatives for Anthropic did not respond to a request for comment from Business Insider.

Hacktron's disclosure comes as AI security is becoming one of the most important topics in tech. In recent months, OpenAI, Anthropic, and Meta have disclosed that their agents engaged in rogue actions during testing. Fears of an AI apocalypse, driven by unchecked malicious AI agents, have emerged in droves this month.

── more in #ai-safety 4 stories · sorted by recency
── more on @hacktron 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/this-tiny-cybersecur…] indexed:0 read:2min 2026-09-18 ·