AIThis post was created with the assistance of artificial intelligence (AI).

🔍 Read the full analysis: OpenAI’s Ethical Hacking Experiment Involved Anthropic’s Claude Chatbot on ThorstenMeyerAI.com

Buying for a business?Offer from Amazon

Get business pricing on monitors, keyboards and dev gear

  • Business-only prices and quantity discounts
  • Tax-exempt purchasing
  • Multiple users, one account, clear invoices
As an affiliate, we earn on qualifying purchases.

TL;DR

OpenAI’s authorized security assessment involved Anthropic’s Claude AI helping researchers access internal accounts and code. The vulnerabilities were fixed, highlighting AI’s role in cybersecurity testing.

OpenAI disclosed that researchers from Hacktron AI used Anthropic’s Claude chatbot during an authorized security test to access employee accounts and parts of its software environment, which led to a vulnerability patch. For more details, see the original analysis. This incident highlights how AI tools are increasingly integral to cybersecurity assessments and can reduce detection and exploitation times.

The security team at Hacktron AI, a three-person research group, conducted the test under OpenAI’s bug-bounty program. They first used Anthropic’s Claude to exploit a weakness in OpenAI’s online discussion forum, hosted on Discourse, which allowed them to gain access to employee ChatGPT accounts. For background on AI security vulnerabilities, see the original analysis. From there, they obtained information about OpenAI’s code storage and management systems.

During the process, the researchers created a harmless pull request in an OpenAI GitHub repository, demonstrating access to code but without downloading or altering sensitive data. The entire operation from initial discovery to repository access took less than 72 hours. OpenAI responded by revoking affected tokens, reducing permissions, and patching the vulnerabilities. The researchers received a $6,500 bounty for their findings.

While Claude played a role in the early stages, Hacktron AI stated that later stages relied heavily on OpenAI’s GPT-5.6 Sol model, indicating human oversight and AI assistance rather than autonomous hacking by the chatbot. The incident was a controlled, authorized test, not an unprovoked attack.

At a glance
reportWhen: disclosed March 2024, incident occurred…
The developmentHacktron AI used Anthropic’s Claude during an authorized security test to access OpenAI employee accounts and internal code repositories, leading to a patch and bounty payout.
At a glance
reportWhen: Reported September 18, 2026; vulnerabil…
The developmentHacktron AI reported an authorized security test in which researchers used Claude to help gain access to OpenAI employee accounts and internal software resources.

Implications of AI-Assisted Security Testing

This incident underscores how AI tools can significantly accelerate security assessments, reducing the time and expertise traditionally required. Hacktron AI claimed that what once took months could now be accomplished in days, raising concerns about the rapid pace of vulnerability discovery and exploitation in AI-enabled environments.

For organizations, this means potential risks extending beyond individual flaws—AI can assist in reconnaissance, code analysis, and linking vulnerabilities across interconnected systems. The incident also emphasizes the importance of securing third-party services like online forums, especially when integrated with employee authentication and development environments.

Furthermore, the case adds to ongoing industry debates about AI safety, as similar incidents have been reported elsewhere. Notably, OpenAI previously disclosed that its AI agents reached the production infrastructure of Hugging Face during a cybersecurity test, illustrating that AI systems and their surrounding infrastructure can create new attack vectors.

Amazon

cybersecurity vulnerability testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on AI Security and Previous Incidents

OpenAI’s security testing practices have evolved alongside the rapid development of AI capabilities. In July 2023, OpenAI disclosed that its AI agents had accessed Hugging Face’s production environment during a controlled test, highlighting potential risks of AI models operating outside isolated environments. Separately, Anthropic reported that its Claude models reached real systems during evaluations after a third-party testing environment was mistakenly connected to the internet.

The Hacktron incident is notable because it involved a human-led, authorized security test where AI tools helped identify and exploit vulnerabilities, contrasting with previous disclosures of AI models operating in evaluation or accidental exposure scenarios. These events collectively demonstrate that both AI systems and their associated infrastructure can be targets or facilitators of security breaches.

“Using AI tools like Claude and GPT-5.6 allowed us to significantly reduce the time needed to identify and access internal systems during the test.”

— Hacktron AI researcher

Amazon

AI security assessment software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Unresolved Details About the Full Scope

It remains unclear how much sensitive information, beyond the code repository and account access, the researchers could have reached. Hacktron AI stated they did not download code, but the full extent of permissions available during the test has not been publicly detailed. Additionally, the precise role of Claude versus human effort in executing the exploit is not fully clarified. OpenAI has not released a comprehensive technical postmortem, leaving questions about the attack chain, duration of exposure, and potential impact on other services.

Amazon

ethical hacking tools for AI systems

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps in Security and Transparency

OpenAI is expected to publish a detailed technical analysis of the incident, including what was accessible and what safeguards were implemented afterward. The company may also review and strengthen its security protocols around community forums, sign-on tokens, and code repositories. For the broader industry, this incident could prompt increased scrutiny of AI-assisted security testing and integration points vulnerable to exploitation. Further disclosures or audits are anticipated to better understand the incident’s full scope and prevent future vulnerabilities.

Amazon

code repository security tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Did the hackers access sensitive user data?

OpenAI has not confirmed whether any sensitive user data was accessed beyond the accounts and repositories reported. The researchers did not download code or data, but the full scope of accessible information remains unclear.

How did AI tools help in the hacking process?

AI tools like Claude and GPT-5.6 Sol were used to identify vulnerabilities, analyze systems, and assist in exploiting weaknesses, significantly reducing the time needed for such assessments.

Will OpenAI face further security breaches?

While OpenAI has addressed the vulnerabilities, the incident highlights ongoing risks in AI infrastructure. The company is expected to review and enhance security measures, but future risks cannot be entirely ruled out.

Is this incident unique to OpenAI?

No, similar risks have been reported elsewhere, such as AI models reaching production systems during evaluations. The trend indicates growing challenges in securing AI environments.

What does this mean for AI safety discussions?

This incident adds to concerns about AI safety, especially regarding how AI tools can assist in security assessments and potentially facilitate malicious activities if misused or exploited.

Primary source: Anthropic · via ThorstenMeyerAI.com

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Show HN: Mindwalk – Replay coding-agent sessions on a 3D map of your codebase

Mindwalk introduces a tool that visualizes and replays coding-agent sessions on a 3D map of codebases, enhancing debugging and collaboration.

Smart Digital Cockpits: The PowerDrive Cortex and Bus Software Platforms

Looking into smart digital cockpits reveals how the PowerDrive Cortex and bus software platforms are transforming vehicle connectivity and safety—discover what makes them revolutionary.

Show HN: Analog Watch

A developer has launched a new project called ‘Analog Watch’ on Show HN, showcasing a minimalist, handcrafted timepiece concept. Details are emerging.

How 5G Technology Is Enhancing Electric Bus Operations

Unlock how 5G technology is revolutionizing electric bus operations, improving efficiency, safety, and passenger experience—discover the future of urban transit.