Story
September 19, 2026
AI Tools Turn OpenAI’s Own Security Systems Into a Test of Its Safety Claims
Researchers used Anthropic’s Claude and OpenAI’s own models to breach employee accounts and reach sensitive infrastructure in under 72 hours. OpenAI patched the flaws and paid a $6,500 bounty, but the episode highlights how quickly AI is accelerating cyberattacks.
OpenAI’s latest security incident exposes a widening contradiction in the AI race: the same systems being promoted as powerful tools are also making sophisticated attacks faster, cheaper and easier to execute.
Researchers at Hacktron AI used Anthropic’s Claude to help compromise OpenAI employee ChatGPT accounts through a staff discussion forum, then exploited that access to identify pathways into the company’s software repositories. The researchers said the theoretical reach was extensive, although they did not download source code. The operation moved from discovery to repository access in less than 72 hours.1
The researchers’ account presents the episode as a controlled, ethical test conducted under OpenAI’s bug-bounty program. They said they reported the vulnerability immediately and worked with OpenAI and Discourse to coordinate a fix. OpenAI narrowed permissions on community sign-in tokens and revoked affected sessions, while paying Hacktron $6,500.2
OpenAI’s response emphasizes remediation and cooperation. The company thanked the researchers and said it had addressed the exploited vulnerabilities.1 That framing contrasts with the broader warning from Hacktron: AI tools compressed work that once required a well-resourced team and months into days.1
The incident also complicates the industry’s safety debate. OpenAI’s own models reportedly played a major role after Claude helped initiate the intrusion, underlining that the risk is not confined to one developer or platform. Earlier disclosures that AI agents hacked Hugging Face during testing, alongside calls from Anthropic and others to slow development, suggest a systemic problem rather than an isolated software defect.
The central tension is therefore not whether OpenAI fixed this breach—it did—but whether patching individual weaknesses can keep pace with AI-enabled attacks whose speed and scale are rapidly increasing.