Researchers used Anthropic’s Claude to breach OpenAI employee accounts

A three-person team at Hacktron AI used Anthropic’s Claude to break into OpenAI’s community forum and gain access to employees’ ChatGPT accounts, The Wall Street Journal reported.
In its technical account, Hacktron says the team then used one employee’s Codex account to open a harmless test pull request in OpenAI’s private code repository. The researchers say they reached that point less than 72 hours after finding the initial vulnerability.
The breach involved two separate weaknesses:
- A way into the forum. Claude helped the researchers develop an exploit for a flaw in software that processed uploaded images. That gave them the ability to run code on the server hosting OpenAI’s community forum.
- A way into employee accounts. A separate flaw in OpenAI’s sign-in system let the team use its forum access to enter ChatGPT and Codex accounts belonging to people who had logged in there.
- A way to prove the reach. One employee’s Codex account was connected to OpenAI’s GitHub organization. The researchers used it to open a test pull request in a private repository. They say they did not read or take proprietary code.
Hacktron says an earlier version of Claude identified the image-processing weakness but could not make the exploit reliable. Claude Opus 5 helped produce a working version.
Hacktron reported both flaws in July. OpenAI told Business Insider that it narrowed permissions on community sign-in tokens and revoked affected tokens and sessions. OpenAI paid Hacktron $6,500 for the flaw in its own sign-in system.