Hacktron team used Anthropic Claude to breach OpenAI systems
A three-person cybersecurity group from Hacktron AI exploited vulnerabilities in an OpenAI forum using Anthropic's Claude chatbot starting on July 23.

Researchers accessed private code repository
The team combined a flaw in the Discourse forum software with a separate issue in the sign-on system. They gained control of employee accounts and demonstrated access to the company's internal code repository without downloading it. OpenAI paid the researchers $6,500 for reporting these vulnerabilities through its bug-bounty programme.
Vulnerability involved image processing tools
The attack relied on corrupted image files processed by ImageMagick and a vulnerable library called libheif. This allowed remote code execution on the forum server before the team stopped testing. OpenAI confirmed it fixed the issues within about 14 hours of being notified.
Newer AI model improved results
Initial attempts used Claude Opus 4.8, but the researchers switched to the newer Opus 5 for consistent success. The operation took less than three days to complete after the launch of the updated model. Hacktron stated they did not use the restricted Mythos version of the software.
7 outlets, different leads
-
Express Tribune
Anthropic's Claude helped cybersecurity researchers breach OpenAI: report
-
Anadolu Agency
Anthropic's Claude helped cybersecurity researchers breach OpenAI: Report
-
The Guardian
OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot
-
Ars Technica
Researchers used Claude to hack OpenAI
-
TechCrunch
Researchers used Anthropic’s Claude to hack into OpenAI
-
Dawn
Researchers used Claude to breach OpenAI's internal systems
-
The Verge
Security researchers used Claude to help them hack into OpenAI
Reported by
7 independent outlets. Headlines as published. Links open the original report.
-
Express Tribune
Anthropic's Claude helped cybersecurity researchers breach OpenAI: report
tribune.com.pk → -
Anadolu Agency
Anthropic's Claude helped cybersecurity researchers breach OpenAI: Report
aa.com.tr → -
The Guardian
OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot
theguardian.com → -
Ars Technica
Researchers used Claude to hack OpenAI
arstechnica.com → -
TechCrunch
Researchers used Anthropic’s Claude to hack into OpenAI
techcrunch.com → -
Dawn
Researchers used Claude to breach OpenAI's internal systems
dawn.com → -
The Verge
Security researchers used Claude to help them hack into OpenAI
theverge.com →