Technology 33 sources · over 4 days Latest coverage 19 Sept 2026, 9:21 am UTC

Security Researchers Breach OpenAI Using Anthropic's Claude Model in 72 Hours

A security team used Anthropic's Claude AI to exploit vulnerabilities in OpenAI systems, exposing employee accounts and internal code, raising urgent concerns about AI-driven cybersecurity threats.

By Claire Dubois · First published 18 Sept 2026

In brief

  1. Three researchers from Hacktron used Anthropic's Claude model to breach OpenAI systems in under 72 hours.
  2. The team exploited vulnerabilities in a third-party service to access OpenAI employee accounts and internal repositories.
  3. Researchers demonstrated their access by initiating a harmless pull request in OpenAI's internal code repository.
  4. OpenAI closed the vulnerability within 14 hours and awarded the researchers a $6,500 bounty for their responsible disclosure.
  5. The incident highlights rising security and safety concerns around advanced AI tools and the importance of robust disclosure programs.
Security Researchers Breach OpenAI Using Anthropic's Claude Model in 72 Hours
Source: The Wall Street Journal Tech

Timeline · 6 moments

6 moments Open the full timeline →

Hacktron begins probing OpenAI systems using Anthropic's Claude model

Публикации по подписке ↗

Researchers exploit Discourse forum flaw to access employee ChatGPT accounts

Digital Trends ↗

Hackers access internal GitHub repositories linked to OpenAI employee accounts

The Wall Street Journal Tech ↗

OpenAI confirms breach and awards $6,500 bug bounty to researchers

Forbes ↗

Incident prompts renewed debate over AI-driven cybersecurity risks

AI - The Guardian ↗

OpenAI patched vulnerability in 14 hours after disclosure

The Next Web ↗

Update 19 Sept 2026, 9:21 am UTC

Recent coverage confirms that three Indian-origin researchers from Hacktron used Anthropic's Claude to breach OpenAI's internal systems and ChatGPT employee accounts. Reports clarify that the attack exploited a third-party service and that OpenAI patched the vulnerability within 14 hours, with no evidence of malicious intent or major damage.

Update 18 Sept 2026, 4:09 pm UTC

New coverage confirms the researchers used Anthropic's Claude to access OpenAI's employee accounts and internal code repositories. The breach exploited a flaw in OpenAI's public help forum, and the team demonstrated access by initiating a harmless pull request. The researchers were identified as Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini.

How it started

The breach began when a team of independent security researchers, operating under the name Hacktron, decided to participate in OpenAI's bug bounty program. Their goal was to find exploitable vulnerabilities in OpenAI's public-facing systems. Instead of relying solely on their expertise, the team leveraged Anthropic's Claude, a rival AI model, to assist in their search for weaknesses.

According to The Wall Street Journal Tech, the researchers targeted OpenAI's Discourse forum, which hosts discussions and support for the company's products. This forum became the entry point for their investigation.

How it unfolded

On July 25, 2026, the Hacktron team began probing OpenAI's systems with the help of Anthropic's Claude model, focusing on the Discourse forum software. They discovered two linked vulnerabilities, one of which allowed them to exploit the forum's authentication process.

Using code generated by Claude, the team managed to access an OpenAI employee's ChatGPT account. This initial breach opened the door to further access, including private GitHub code repositories connected to the compromised accounts, as reported by Digital Trends.

The entire process, from identifying the vulnerability to gaining access, took less than 72 hours, underlining the speed with which modern AI tools can accelerate both attack and defense in cybersecurity, according to TechRadar.

After confirming the extent of their access, the researchers responsibly disclosed the vulnerabilities to OpenAI as part of the company's bug bounty program. OpenAI reviewed their findings and verified the breach, which involved sensitive internal code and employee accounts.

Where it stands

OpenAI responded quickly to the disclosure, patching the vulnerabilities and awarding Hacktron a $6,500 bug bounty for their work. The company has not reported evidence of malicious exploitation beyond this ethical hacking demonstration.

The incident has sparked debate in the tech community about the growing capabilities of AI models in both offensive and defensive cybersecurity roles. It also prompted renewed scrutiny of the security of AI-driven platforms and the importance of robust vulnerability disclosure programs.

What to watch

Observers are watching to see how OpenAI and other AI companies will adapt their security practices in the wake of this breach. The case may influence how future AI bug bounty programs are designed and could accelerate efforts to secure AI-powered platforms against similar attacks.

Written from 33 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →