en
Back to the list

OpenAI Hacked Using Anthropic’s Claude, Hackers Confirmed It

source-logo  coinpedia.org 55 m
image

A three-person team has hacked OpenAI after they used Anthropic’s Claude to help exploit a flaw linked to the company’s community forum. The team gained access to an OpenAI employee’s ChatGPT account and reached the company’s internal GitHub environment before reporting the issue to OpenAI.

Here are the details of the Hack.

Hackers Confirm OpenAI Breach

On X, AI researcher s1r1us confirmed that the team breached OpenAI on July 25, 2026.

The Hacktron AI team chained two vulnerabilities to take over ChatGPT and Codex accounts linked to OpenAI employees and some unrelated users. These accounts also had access to connected services such as Outlook, Slack, and GitHub.

On July 25, we hacked OpenAI.

Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.

We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵 pic.twitter.com/gVsmQZwSc8

— s1r1us (@S1r1u5_) September 18, 2026

The team said the entire process from finding the vulnerability to reaching OpenAI’s internal repository took less than 72 hours.

“On July 25, we hacked OpenAI. It took us <72h.”

As proof, we created a pull request in OpenAI’s internal codebase.

How the Claude-Assisted OpenAI Breach Happened?

The attack began on July 23 with a vulnerability in the image-processing system used by Discourse, the third-party software hosting OpenAI’s community forum.

The team first used Claude Opus 4.8 to help build an exploit, but the model struggled to bypass address-space layout randomization, a security feature designed to make memory attacks harder.

After Anthropic released Claude Opus 5 the next day, the researchers switched models and said it helped them create a working ARM64 exploit within hours.

The exploit allowed the team to steal active authentication tokens from the discussion server. They then used those credentials to access an OpenAI employee account and reach private GitHub repositories. The researchers said the full attack chain took less than 72 hours.

OpenAI’s Response

OpenAI confirmed the incident and said it narrowed permissions on community sign-in tokens, revoked affected sessions, and fixed the image-processing flaw. The company said no customer data or proprietary AI model weights were compromised.

Discourse also patched the underlying vulnerability and added additional protection around image processing.

Who Was Behind the Attack?

The breach was carried out by a three-person team of cybersecurity researchers from Hacktron AI. The team found and exploited the security flaws as part of an authorized white-hat bug bounty program, not as a criminal attack.

Meanwhile, OpenAI later paid the researchers a $6,500 bounty for reporting the vulnerabilities.

coinpedia.org