Between July and September 18–20, 2026, Hacktron AI security researchers used Anthropic's Claude models to chain vulnerabilities in OpenAI's community forum and authentication systems, gaining access to employee ChatGPT accounts. OpenAI paid a $6,500 bug bounty for the discovery.
12 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Three Hacktron AI security researchers used Anthropic’s Claude models to chain vulnerabilities in OpenAI’s community-forum infrastructure and authentication systems, gaining access to employee ChatGPT accounts and an internal GitHub repository. The researchers began on July 23 by examining how the Discourse-based forum processed HEIC and HEIF images. After Claude Opus 4.8 failed to produce a relia
Three researchers from cybersecurity startup Hacktron AI used Anthropic’s Claude models in July to chain together vulnerabilities in OpenAI’s public community forum and identity systems, gaining control of several employee ChatGPT and Codex accounts and access to an internal GitHub repository. The work took place under OpenAI’s bug-bounty program, and the researchers reported the access rather tha
Three researchers at cybersecurity startup Hacktron AI used Anthropic’s Claude models to exploit vulnerabilities in OpenAI’s public community forum and access several employee ChatGPT and Codex accounts, according to the researchers and reporting by The Wall Street Journal. The operation, conducted through OpenAI’s authorized bug-bounty program, provided a path to an internal GitHub repository. Th
OpenAI paid the researchers a $6,500 bug bounty, but the incident once again highlights the growing cybersecurity threats posed by advanced AI agents. OpenAI paid the researchers a $6,500 bug bounty, but the incident once again highlights the growing cybersecurity threats posed by advanced AI agents.
Hacktron researchers used Anthropic’s Claude models to chain vulnerabilities in OpenAI’s public community forum and sign-in system, gaining access to several OpenAI employees’ ChatGPT and Codex accounts and a private software repository. The work took place under OpenAI’s bug-bounty program, and the researchers said they neither downloaded nor inspected proprietary source code. They demonstrated r
[Shocking] Claude Hacks ChatGPT! Fatal Vulnerabilities Exposed in Under 72 Hours and the Reality of AI Threats ▼Read More https://biz-matome.com/archives/56526 Software security researchers hacked OpenAI's ChatGPT using Anthropic's Claude AI. Hacktron AI revealed they gained access to OpenAI employee accounts, source code repositories, and discussion forums in under 72 hours. OpenAI quickly addres
Hacktron AI, a three-person cybersecurity startup, used Anthropic’s Claude models to exploit a vulnerability in the Discourse forum used by OpenAI. The researchers took control of multiple OpenAI employees’ ChatGPT accounts, accessed the company’s internal software environment and demonstrated that access with a harmless pull request, but said they did not download source code or deploy malicious
‼️ Claude Opus 5 helped three researchers build an image exploit that took over OpenAI's public help forum server. A flaw in OpenAI's own login then let them take over staff ChatGPT/Codex accounts and reach an internal code repo — in under 72 hours. Here's how the chain worked → https:// thehackernews.com/2026/09/clau de-opus-5-helped-researchers-take.html
🔹 The Hacker News Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum
Hacking OpenAI | Hacktron AI Hacktron AI chained a Discourse/libheif vulnerability to gain remote code execution on OpenAI’s forum and access an employee’s Codex account, enabling entry to OpenAI’s internal repos; OpenAI patched the flaw and paid a $6,500 bug bounty. https://www. hacktron.ai/blog/hacking-openai
techcrunch.com/2026/09/18/r... Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.