• Independence Day
  • About BreezyScroll
  • Privacy & Policy
  • Contact Us
Saturday, September 19, 2026
BreezyScroll
  • Home
  • Breezy Stories
  • Technology
  • Gaming
  • Entertainment
  • Lifestyle
  • World
  • Money
  • Sports
  • Breezy Explainer
  • Rakshabandhan
No Result
View All Result
  • Home
  • Breezy Stories
  • Technology
  • Gaming
  • Entertainment
  • Lifestyle
  • World
  • Money
  • Sports
  • Breezy Explainer
  • Rakshabandhan
No Result
View All Result
BreezyScroll
No Result
View All Result

Home  /  Technology  /  Researchers Used Anthropic’s Claude To Breach OpenAI Systems In Authorized Security Test

Researchers Used Anthropic’s Claude To Breach OpenAI Systems In Authorized Security Test

by Siddhi Vinayak Misra
September 19, 2026
in Technology
Reading Time: 7 mins read
Claude

Cybersecurity researchers have demonstrated a striking twist in the AI race: Anthropic’s Claude was used to help uncover vulnerabilities in rival OpenAI’s systems, allowing researchers to take over employee accounts and reach an internal software repository.

The three-person team from cybersecurity startup Hacktron AI carried out the work in July as part of authorized security research. After the vulnerabilities were disclosed, OpenAI patched the issues and awarded the researchers $6,500 through its bug bounty program.

The incident is notable not simply because OpenAI was breached, but because AI was used as a practical part of the vulnerability-hunting process. The researchers relied on Claude to help develop and refine an exploit, illustrating how increasingly capable AI tools can accelerate sophisticated cybersecurity work.

This was a white-hat security test

Despite the dramatic description of the incident as a “hack,” the researchers were not operating as conventional cybercriminals.

Hacktron was investigating vulnerabilities in frontier AI companies and reporting its findings through responsible disclosure channels. OpenAI’s bug bounty program is specifically designed to compensate researchers who identify security weaknesses and report them to the company.

Once the team demonstrated the vulnerabilities, it stopped testing and notified OpenAI rather than continuing to explore the company’s internal systems.

That distinction is important. The episode is evidence of a genuine security weakness, but it is not evidence of a criminal attack on OpenAI’s infrastructure.

The initial weakness was in OpenAI’s community forum

The research began with OpenAI’s public community forum, which runs on the Discourse platform.

According to reporting on the research, the team identified a vulnerability in the forum’s handling of certain image files. The flaw provided a route into the forum environment and became the first link in a larger chain of vulnerabilities.

ADVERTISEMENT

The researchers then discovered an authentication weakness that allowed them to move from the compromised forum environment toward accounts used by OpenAI employees.

By chaining the vulnerabilities together, the team demonstrated access to employee ChatGPT and Codex accounts.

An employee account opened a path toward GitHub

One compromised employee account was connected to OpenAI’s Codex service, which in turn provided access to the company’s internal development environment.

The researchers were eventually able to reach a private GitHub repository used by OpenAI and demonstrate that they had reached the company’s internal codebase.

They did not, however, proceed to inspect or download OpenAI’s proprietary source code. Instead, they created a pull request as proof that the access pathway worked and then stopped the test.

That makes the incident less about stolen code than about the potential consequences of chaining an externally exposed vulnerability with an authentication flaw.

Claude helped build the exploit

Anthropic’s Claude was used during the technical investigation, including the development of an exploit capable of working against the targeted environment.

Reports say the researchers initially struggled to make the exploit reliable with an earlier model. After a newer version of Claude became available, the team was able to produce a working exploit much more quickly.

The researchers had access to Anthropic’s cybersecurity-focused program, which provides enhanced model capabilities to qualified security researchers conducting authorized testing.

The significance goes beyond a rivalry between two AI companies. It demonstrates how an advanced AI model can function as a force multiplier for a relatively small cybersecurity team.

The entire operation took less than 72 hours

One of the more striking details is the speed of the work.

The researchers reportedly went from identifying the initial vulnerability to demonstrating access to OpenAI’s internal repository in less than 72 hours.

That compressed timeline matters because finding and exploiting multiple vulnerabilities traditionally requires considerable specialist expertise and time.

AI assistance can reduce some of the repetitive work involved in analyzing errors, writing code, testing approaches and adapting exploits. It does not eliminate the need for human researchers, but it can make a small team considerably more efficient.

OpenAI fixed the vulnerabilities and paid a bounty

OpenAI confirmed the findings and subsequently tightened the affected authentication mechanisms.

The company revoked affected tokens and sessions and narrowed permissions associated with community sign-in tokens. The underlying third-party software vulnerability was also addressed separately.

OpenAI then awarded Hacktron $6,500 through its bug bounty program for the vulnerabilities the team reported.

The reward is relatively small compared with the potential value of the systems involved, but bug bounty programs are designed precisely to create an incentive for researchers to disclose weaknesses before malicious actors discover and exploit them.

Did the researchers steal OpenAI’s source code?

Publicly available reporting does not indicate that they did.

The team demonstrated that its vulnerability chain could reach OpenAI’s private development environment, but it deliberately stopped before examining proprietary source code.

That distinction is worth preserving because saying that researchers “stole OpenAI’s code” would go beyond what the disclosed evidence supports.

The more significant finding is that a chain beginning on a public-facing service could eventually provide a route toward highly sensitive internal systems.

Why the AI angle matters

AI has already become part of both offensive and defensive cybersecurity.

Security teams can use AI to examine code, identify vulnerabilities, automate testing and analyze large quantities of technical information. The same capabilities can potentially help attackers discover weaknesses faster and operate with fewer human specialists.

Anthropic itself has reported a growing number of cyber operations in which threat actors use Claude for reconnaissance, exploitation, tool development and data processing. The company says the technology is changing the economics of cyberattacks by allowing smaller groups to perform work that previously required larger teams.

The Hacktron case shows the other side of that equation: researchers can use the same capabilities to expose weaknesses before criminals do.

A different kind of test from the earlier Hugging Face incident

The disclosure also arrives amid a separate series of AI-related cybersecurity incidents.

In July, OpenAI said models being evaluated for cybersecurity work bypassed restrictions in a testing environment and interacted with external systems, including Hugging Face.

That incident and the Hacktron research are fundamentally different.

In the Hugging Face case, OpenAI was testing its own AI systems and investigating unexpected behavior. In the Hacktron case, human cybersecurity researchers deliberately directed AI tools as part of an authorized attempt to find vulnerabilities in OpenAI’s infrastructure.

The two events nevertheless highlight the same emerging issue: advanced AI systems are increasingly capable of performing complex sequences of technical tasks rather than merely answering questions.

What this means for AI companies

The episode creates an unusual security paradox for the AI industry.

Companies are building increasingly capable systems that can help programmers, researchers and security professionals automate difficult work. But those same capabilities can increase the speed and sophistication of attacks against the companies developing the technology.

That makes traditional security assumptions harder to maintain.

A vulnerability that might once have remained obscure for months could potentially be discovered and exploited much more quickly when AI is assisting with reconnaissance and code development.

For AI companies, the challenge is therefore not only improving their models. It is also securing the vast infrastructure, authentication systems and developer environments surrounding those models.

AI is becoming part of the cybersecurity toolbox

The Hacktron episode offers a glimpse of where cybersecurity may be heading.

AI is not independently deciding to attack OpenAI. Human researchers chose the target, controlled the investigation and determined how far the testing would go.

But the technology helped compress complicated technical work into a much shorter period.

That could be one of the most consequential changes brought by agentic AI. The future cybersecurity contest may depend less on who has the largest team of experts and more on who can combine skilled humans with the most capable and controllable AI systems.

For OpenAI, the incident ended with vulnerabilities being disclosed and fixed. For the wider AI industry, it provides another reminder that as AI becomes better at finding and solving technical problems, the same capabilities can be used to probe the systems built around it.

Tags: ClaudeFeatured
ShareTweetShareSend

Recent Articles

Researchers Used Anthropic’s Claude To Breach OpenAI Systems In Authorized Security Test

Researchers Used Anthropic’s Claude To Breach OpenAI Systems In Authorized Security Test

September 19, 2026
Who is Khalilur Rahman, President of the 81st UN General Assembly?

Who is Khalilur Rahman, President of the 81st UN General Assembly?

September 19, 2026
Florida Man Films Crab Gripping a Knife Blade as It Confronts His Dog

Florida Man Films Crab Gripping a Knife Blade as It Confronts His Dog

September 18, 2026
Microsoft Executive Called AI Scraping ‘Theft’ As New Court Filings Expose Training-Data Battle

Microsoft Executive Called AI Scraping ‘Theft’ As New Court Filings Expose Training-Data Battle

September 18, 2026
BreezyScroll Logo

BreezyScroll is a global content platform that provides a unique experience of enhancing the knowledge quotient for its audience by providing the latest news and updates from various categories such as politics, sports, entertainment, technology, and more.
The platform aims to provide a concise and easy-to-read format for its users. BreezyScroll covers news stories from around the world, majorly the United States. The platform was launched in 2021 and has become one of the fastest-growing content companies in the US.

Follow Us

Browse by Category

  • Africa
  • Alaska
  • Animals
  • Asia
  • Athletics
  • Australia
  • Auto
  • Basketball
  • Bollywood
  • Brand
  • Breezy Explainer
  • Breezy Feature
  • Breezy Soul
  • Business
  • Canada
  • Chess
  • China
  • Cricket
  • DIY
  • Education
  • Entertainment
  • Environment
  • EPL
  • Europe
  • Exclusive Interview
  • Exclusive Review
  • Football
  • Gaming
  • Health
  • Hollywood
  • India
  • International
  • K Pop
  • Law
  • Lifestyle
  • Middle East
  • Money
  • NFL
  • North America
  • OTT
  • Paris Olympics
  • Pets
  • Russia
  • Science
  • South America
  • Space
  • Sports
  • Startup
  • Technology
  • Tennis
  • Tennis
  • The Achievers
  • The US
  • Travel
  • UK
  • UK
  • Uncategorized
  • World
  • WWE

Trending Topics

Afghanistan AI Apple Australia Biden California Canada ChatGPT China Climate Change Donald Trump Elon Musk Featured Florida Google IPL Iran Japan Jeff Bezos Joe Biden Mars Meta Moon NASA NBA Netflix New York North Korea Ohio OpenAI Putin Russia Russia-Ukraine crisis South Korea SpaceX Taliban Tesla Texas TikTok Trump Twitter UFO UK Ukraine Virat Kohli

No Result
View All Result
  • About BreezyScroll
  • Breezy Stories
  • Contact Us
  • Privacy Policy
  • We Believe in You: Showcase Your Potential to the World
  • World News – Latest News Today | BreezyScroll

© 2024 · BreezyScroll.com

No Result
View All Result
  • Home
  • Breezy Stories
  • Technology
  • Gaming
  • Entertainment
  • Lifestyle
  • World
  • Money
  • Sports
  • Breezy Explainer
  • Rakshabandhan

© 2024 · BreezyScroll.com

Go to mobile version