Technology
The Verge

Security researchers used Claude to help them hack into OpenAI

Source Entity

Stevie Bonifield

September 20, 2026
Security researchers used Claude to help them hack into OpenAI

Security researchers from Hacktron AI successfully exploited vulnerabilities in OpenAI's systems using Anthropic’s Claude chatbot. The ethical hack, conducted under a bug-bounty program, exposed critical access flaws that have since been patched by OpenAI.

The Weaponization of AI in Cybersecurity

The recent breach of OpenAI by researchers from the startup Hacktron AI marks a significant milestone in the evolution of digital threats. By leveraging Anthropic’s Claude chatbot to identify and exploit vulnerabilities, these researchers have demonstrated a paradoxical new reality: the very tools designed to advance artificial intelligence are now being utilized to compromise the infrastructure of its most prominent developers.

Mechanics of the Breach

The attack vector was multifaceted, utilizing a combination of social engineering and technical exploitation. The researchers first gained access to OpenAI employee ChatGPT accounts via an internal discussion forum hosted on the Discourse platform. By chaining these initial access points with a malicious yet "harmless" pull request on a GitHub software repository, the team was able to navigate the company's internal software cache. This sequence of events underscores the fragility of modern development pipelines when subjected to AI-augmented reconnaissance.

The Role of Claude as an Offensive Tool

What makes this incident particularly striking is the use of Claude, a direct competitor to OpenAI’s ChatGPT, as an offensive tool. The research team utilized Claude’s sophisticated code-generation capabilities to streamline the process of identifying and exploiting system weaknesses. This highlights the dual-use nature of Large Language Models (LLMs), which are increasingly capable of automating complex cyberattacks that would previously have required human expertise and significantly more time.

Institutional Response and Accountability

It is important to note that this breach was conducted under the auspices of a formal bug-bounty program. Hacktron AI received a $6,500 reward for their findings, and OpenAI has confirmed that the vulnerabilities have been successfully remediated. This collaborative approach between independent security firms and major AI labs serves as a critical mechanism for fortifying software defenses before malicious actors can cause real-world damage.

Broader Implications for AI Security

This incident arrives at a time of heightened global scrutiny regarding the safety and security of frontier AI models. As these labs race to develop more powerful systems, the attack surface expands exponentially. The ability of a small team to breach one of the world's most sophisticated AI organizations suggests that even the highest-resourced companies are not immune to the rapid advancement of AI-assisted hacking techniques.

Future Trends in Defensive AI

Looking forward, we can expect a continued "arms race" in the domain of AI cybersecurity. As hackers integrate LLMs into their workflows to discover zero-day exploits, organizations will be forced to adopt AI-driven defense systems capable of monitoring for anomalous behavior in real-time. The Hacktron AI incident serves as a necessary wake-up call, emphasizing that the future of software security will be defined by the speed at which developers can out-innovate the very tools they have created.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to The Verge