Technology
TechCrunch

Researchers used Anthropic’s Claude to hack into OpenAI

Source Entity

Aditya Mehta, Rebecca Bellan

September 19, 2026
Researchers used Anthropic’s Claude to hack into OpenAI

Cybersecurity researchers from Hacktron AI successfully breached OpenAI systems by using Anthropic's Claude chatbot to exploit vulnerabilities. The incident, which allowed access to employee accounts and internal code repositories, has been resolved through OpenAI's bug-bounty program.

The AI-Powered Cyber Breach: A Paradigm Shift in Security

In a landmark event that underscores the evolving landscape of digital warfare, a security team from the startup Hacktron AI successfully breached OpenAI’s internal systems. This incident is particularly notable because the researchers utilized Anthropic’s Claude—a primary competitor to OpenAI’s ChatGPT—to facilitate the exploit. By leveraging Claude’s code-generation capabilities, the researchers were able to identify and chain together critical vulnerabilities, effectively turning one AI giant’s technology against another.

The Mechanics of the Breach

The attack began with the researchers targeting OpenAI employee accounts hosted on the Discourse platform. By using Claude to generate the necessary code and strategies, the team managed to bypass existing defenses, eventually gaining unauthorized access to internal software caches. Once inside, they escalated their reach by making a 'pull request' to OpenAI’s GitHub repository. This effectively provided them with access to sensitive internal code, demonstrating a significant flaw in the company’s peripheral security infrastructure.

The Role of Bug-Bounty Programs

It is essential to note that this breach was not a malicious act by cybercriminals, but a controlled penetration test conducted under the auspices of OpenAI’s official bug-bounty program. The Hacktron AI team, consisting of three researchers, systematically documented their findings and reported them to OpenAI. For their efforts in exposing these critical gaps, the startup was awarded $6,500. This collaborative approach highlights the industry standard of incentivizing 'white hat' hackers to find systemic flaws before they can be weaponized by bad actors.

Implications for AI Safety and Governance

The ability of an AI model to assist in the compromise of a rival company’s security infrastructure raises profound questions regarding the dual-use nature of generative AI. As these models become more sophisticated at writing complex code, the barrier to entry for cyberattacks is being lowered. If an AI can be used to scan for vulnerabilities or craft sophisticated social engineering scripts, the cybersecurity industry must rapidly adapt its defensive paradigms to account for 'AI-augmented' threats.

Future Trends in AI Defense

This incident serves as a wake-up call for the broader AI sector, which currently faces intense scrutiny from regulators and the public regarding safety standards. As OpenAI works to resolve these specific vulnerabilities, the industry will likely shift toward more rigorous internal auditing and the implementation of 'AI-resistant' security protocols. Moving forward, we can expect to see a rise in security-focused AI tools—similar to the specialized version of Claude used in this experiment—designed specifically to fortify rather than exploit software architectures.

Conclusion

While OpenAI has successfully addressed the vulnerabilities identified by Hacktron AI, the event remains a cautionary tale about the speed at which AI-driven threats are evolving. The intersection of competitive AI models and cybersecurity necessitates a new, more proactive approach to organizational defense. As AI companies continue to race toward AGI, the security of their internal code and employee access points must remain a foundational priority to prevent catastrophic breaches by foreign adversaries or malicious entities.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to TechCrunch