Researchers Use Anthropic's Claude to Hack OpenAI
Security researchers successfully leveraged Anthropic's Claude AI to compromise OpenAI employee accounts and access internal codebases for a bug bounty.
Researchers from the cybersecurity startup Hacktron successfully hacked into OpenAI using Anthropic's Claude AI. The team compromised multiple employee accounts and accessed the company's codebase before the vulnerability was resolved.
What Happened
On July 25, 2026, Indian-origin researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini from the cybersecurity startup Hacktron targeted frontier AI companies. Using Anthropic's Claude AI models, the team managed to compromise multiple OpenAI employees' ChatGPT accounts.
During the security breach, the researchers utilized an employee's Codex account to open a pull request directly in OpenAI's codebase. OpenAI responded by fixing the underlying flaws within 14 hours of discovery and subsequently awarded the startup a $6,500 bounty, equivalent to approximately Rs 6.2 lakh.
Key Details
- Date of incident: July 25, 2026
- Vulnerability mechanism: A flaw in OpenAI's single sign-on (SSO) identity setup combined with a remote code execution bug in Discourse
- Bounty amount: $6,500 (about Rs 6.2 lakh)
- Resolution time: OpenAI fixed the flaw in 14 hours
- Key products and tools involved: Claude, ChatGPT, Codex, Claude Opus 4.8, Claude Opus 5, Discourse, GitHub, and Slack
Why It Matters
The incident demonstrates the practical application of frontier AI models in uncovering complex cybersecurity vulnerabilities across major technology platforms. Following the discovery, OpenAI confirmed that it narrowed the permissions on Community sign-in tokens and successfully revoked all affected tokens and sessions, while formally thanking the Hacktron researchers for sharing their findings.
What We Know So Far
All reported details are confirmed facts based on disclosures from the researchers and OpenAI. There are no unconfirmed reports or speculation noted regarding this incident.