Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Researchers Use Anthropic’s Claude to Hack OpenAI Systems in Security Test

Researchers Use Anthropic’s Claude to Hack OpenAI Systems in Security Test

Last updated:September 18, 2026
Human Written
  • Security researchers at Hacktron AI used Anthropic’s Claude model to help them hack into systems linked to OpenAI.

  • The team got access to OpenAI staff accounts and found a path into the company’s private code storage.

  • OpenAI fixed the flaws, revoked the affected logins, and paid Hacktron for reporting the issue.

Researchers Use Anthropic’s Claude to Hack OpenAI Systems in Security Test

A cybersecurity firm called Hacktron AI recently ran a security test on OpenAI. The team used Anthropic’s Claude model to help them find and use weak spots in OpenAI’s systems. Their work gave them access to OpenAI staff accounts and opened a path into the company’s private code storage.

The Financial Times and the Wall Street Journal both reported on the test. It started in July 2026. Hacktron researchers were looking into OpenAI’s community discussion board. That board runs on a separate platform called Discourse, built by another company.

Details of the Security Test

Hacktron did not attack OpenAI’s main systems directly. Instead, they focused first on the Discourse-based forum that OpenAI uses for public discussions. This forum sits outside OpenAI’s core software, but it still connects to real OpenAI accounts.

The researchers found a flaw in how the forum handled certain image files. This flaw lets them run harmful code on the forum’s servers. Discourse has since fixed that specific problem, according to VentureBeat.

Once inside the forum’s system, the team spotted a second issue. This one involved how OpenAI’s sign-in process worked with the forum. The flaw let them grab login tokens tied to people who had signed into the community board using their OpenAI accounts.

Those tokens gave Hacktron access to several OpenAI employee accounts on ChatGPT and Codex, OpenAI’s coding tool. From there, the team found a route into OpenAI’s private GitHub, where the company stores its software code.

How Claude Helped Build the Exploit

Anthropic makes Claude, an AI model built for chat and coding tasks. Hacktron used a security-focused version of Claude to help write the code needed to exploit the image-file flaw. The model helped speed up work that would normally take a human much longer.

It matters to note that Claude did not act on its own. Human researchers guided every step of the test. They used Claude as a tool, the same way someone might use a calculator or a search engine. The people at Hacktron decided what to target and when to stop.

This part of the story worries some experts. AI models can now help skilled researchers find and use complex bugs much faster than before. That speed could help defenders patch systems sooner. It could also help attackers move faster, too.

AI-assisted hacking has also appeared in incidents outside controlled security tests. In a separate case, Anthropic AI hacked three real organizations after an internet access error, showing how quickly an AI model can move from helping with cybersecurity tasks to interacting with real-world systems.

Even so, Hacktron stopped short of digging into OpenAI’s actual source code. The team wanted to prove the access existed without causing real harm. So they created a harmless pull request instead. A pull request is a proposed change to a piece of code. Theirs simply suggested an edit to a documentation file, not to any working software.

OpenAI later reviewed what happened on its end. The company found that the researchers had read some private repository details and small code changes, based on reporting from the Wall Street Journal. OpenAI said this exposure stayed limited.

OpenAI’s Response and Next Steps

OpenAI confirmed that it fixed both issues once Hacktron reported them. The company tightened the rules around tokens created through the community forum sign-in process. It also cancelled the affected tokens and logged out anyone using them, according to Business Insider.

Hacktron reported its findings through OpenAI’s official bug bounty program. Companies use these programs to reward researchers who find flaws and report them safely, instead of selling that information or causing damage. OpenAI paid Hacktron $6,500 for the work, the Financial Times reported.

This whole event counts as an authorized security test, not a real attack. Hacktron worked within the rules of OpenAI’s program the entire time. No customer data or public user information came under threat during the test.

Still, the case shows how much AI tools now shape the world of cybersecurity. Companies build these models to help people code faster and solve problems. Those same tools can also help trained researchers spot and use security gaps in record time.

For now, both companies say the specific bugs involved are closed. OpenAI has tightened its sign-in system. Discourse has patched the image-file flaw that started the whole chain of events. Anthropic has not shared extra comments about how its model performed during the test beyond what the reports describe.

Experts expect more stories like this one in the months ahead. As AI models grow more capable, more security teams will likely use them to test their own defenses before real attackers find the same weak spots first.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.