Advertisement

Claude used to hack into OpenAI by security researchers: Here’s how it unfolded

AI By Aadeetya Sriram
Last Updated: 2026-09-18 14:42:06
SHARE
Facebook
Twitter
Whatsapp

Anthropic’s Claude has made the headlines this week and folks at OpenAI are likely to be concerned about its prowess and ability to break into other systems. A new report by Wall Street Journal claims a small group of security researchers have used Claude AI to break into the ChatGPT account of OpenAI employees and even managed to access the private codebase of the company.

aiSummary

Show AI Summary

Summarized by AI.
  • bulletsClaude AI used to hack OpenAI employee accounts.
  • bulletsResearchers accessed private codebase via vulnerabilities.
  • bulletsOpenAI fixed issues; paid $6,500 bug bounty.
search

The group was part of OpenAI’s bug bounty program which allowed them to get paid for the vulnerabilities discovered in ChatGPT and Claude AI became their choice of weapon to hack them.

How researchers hacked into ChatGPT accounts 

The report says researchers from a startup called Hacktron AI got access to the employee’s ChatGPT account. The researchers said they did not access sensitive code or data and claimed the full activity was operated in less than 72 hours.

Related Articles

The researchers mentioned that two vulnerabilities allowed them to take control of ChatGPT and Codex accounts belonging to OpenAI employees, which offered them access to connected services such as GitHub, Slack and Outlook.

The vulnerabilities were linked to OpenAI’s community forum system. The researchers said they initially attempted to develop an exploit using Anthropic’s Claude Opus 4.8 model, but the AI struggled to generate a reliable attack method. But after the release of the more capable Claude Opus 5 model, the team retried the task and was able to produce a working exploit within hours.

OpenAI gets to close the loophole 

OpenAI acknowledged the findings and highlighted its efforts to address the vulnerabilities. According to the report, the company made sure the permissions were limited to community sign-in tokens, and implemented fixes to avoid similar attacks.

The researchers, for their efforts and findings, received a bug bounty payment of $6,500 (Rs 6.24 lakh approx) for reporting the issue.

The incident is being viewed as a significant example of how powerful AI systems can accelerate cybersecurity research as well as cyberattacks. Experts warn that as frontier AI models become increasingly capable, tasks that once required highly specialised teams and weeks of work may be completed in a matter of days.

Latest News