Researchers Used Anthropic’s Claude to Hack OpenAI in Bug-Bounty Test
Security researchers at Hacktron AI used Anthropic’s Claude to breach OpenAI employee accounts via Discourse flaws, then reported it under OpenAI’s bug-bounty program. OpenAI fixed the issues and paid $6,500.
The Wall Street Journal first reported the incident Thursday evening, TechCrunch said. According to Hacktron’s blog, the entry point was found on July 25 in Discourse, the third-party software that powers OpenAI’s community forum. A mundane image upload opened the path. When users posted HEIF or HEIC files, the format iPhones use by default, Discourse passed them through ImageMagick, an open-source image utility, which handed the file to a library called libheif for decoding. A memory bug in libheif caused it to miscalculate the positioning of one image over another, allowing a specially crafted image to hijack the server.
The bug had already been fixed months earlier by libheif’s developers, but the fix was never formally flagged as a vulnerability and never received a CVE number, Hacktron said. That may explain why the version used by Discourse was still vulnerable. Once inside the Discourse server, the researchers found a second flaw that let them take over users’ ChatGPT and Codex accounts, including OpenAI employees’ accounts. “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” Hacktron wrote. The researchers alerted OpenAI and Discourse, which issued a fix on July 27. OpenAI says the issues have been resolved.
The AI models used in the attack changed the timeline. Hacktron said the Claude model it was using, a special version of Opus 4.8 made available for cybersecurity researchers, could not build a working exploit at first. That changed when Anthropic released Opus 5. “Opus 4.8 struggled across several sessions to produce a working exploit,” Hacktron wrote. “Within hours of Opus 5’s release, we gave it the same problem and it succeeded.” The Guardian reported that, despite initial use of Claude, the researchers said they largely used OpenAI’s own GPT-5.6 Sol model to carry out the hack. TechCrunch’s account emphasized Claude Opus 5 as the model that produced the working exploit. Hacktron stressed that it had access to, but did not download, code from the GitHub repository.
An OpenAI spokesperson said: “We thank the researchers for contacting us and sharing their findings.” Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the startup said. Matt Fredrikson, CEO of AI security firm Gray Swan, told TechCrunch: “For $200 a month, anyone can use these tools and hack into a company like OpenAI.” He added: “If it can happen to them — and I don’t think they’ve been slouching recently on cybersecurity hygiene — it could happen to anyone.”
The incident put attention on model capabilities and export controls. Claude Opus 5, the version that ultimately cracked the bug, has not faced security export restrictions, unlike newer version Mythos 5, which was temporarily locked down over concerns about advanced hacking capabilities, TechCrunch reported. AI safety nonprofit SaferAI recently found that Chinese company Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7. Hacktron founder Mohan Pedhapati wrote on X: “AI is reducing the amount of scarce expertise needed to develop exploits. Work that once took months can now take days.”
The breach is the latest safety incident at OpenAI. In July, the company revealed that a “swarm” of agents powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test, The Guardian reported. This week, the San Francisco-based company revealed six more examples of “unexpected or concerning” actions by its technology and warned that development could not continue at “maximum speed for much longer.” Anthropic made a fresh call at the weekend for a slowdown in AI development, supported by OpenAI, Google DeepMind and Elon Musk, and repeated warnings that unrestrained AI development poses an existential threat. Donald Trump rejected calls for a slowdown, citing a need to stay ahead of China’s AI industry and dismissing “negative forces … bringing up things that won’t happen.”
Editor's Summary Hacktron AI used AI models including Anthropic’s Claude to breach OpenAI employee accounts through vulnerabilities in Discourse and a connected GitHub organization, then reported the findings under OpenAI’s bug-bounty program. OpenAI fixed the issues and paid $6,500, but the incident highlights how readily available AI tools are shortening the time and expertise needed to develop exploits. It also adds to recent safety warnings from OpenAI and Anthropic while drawing political resistance to slowing AI development.