A cybersecurity team recently gained unauthorized access to OpenAI’s internal systems by exploiting vulnerabilities through Anthropic’s software, raising fresh concerns about the security of leading artificial intelligence (AI) companies. The breach, which involved researchers paid to test OpenAI’s defenses, allowed them to access an employee’s ChatGPT account and review private software details.
The incident occurred as part of a bug bounty program in which OpenAI compensates ethical hackers for identifying weaknesses before malicious actors can exploit them. The three researchers from the security firm Hacktron AI were paid $6,500 for their work. They used a tool from Anthropic, a key competitor of OpenAI, designed specifically for security professionals engaged in vulnerability testing.
The breach was made possible by a flaw in the configuration of OpenAI’s community forum, which is hosted on the third-party platform Discourse. The researchers leveraged the vulnerability to advance from the forum into internal sign-on systems, ultimately gaining access to a ChatGPT account linked to GitHub repositories containing OpenAI’s source code.
OpenAI acknowledged the discovery and said the vulnerability has been addressed. The company expressed gratitude to the researchers for responsibly reporting the issue. Anthropic declined to comment on the matter, while Hacktron AI did not immediately respond to requests for comment.
This security lapse comes amid growing apprehension about the risks posed by powerful AI models, which have increasingly attracted scrutiny from governments and industry observers. In recent months, the U.S. government has grappled with how best to regulate the release and vetting of advanced AI tools, including temporarily restricting some Anthropic products.
The breach follows an incident two weeks earlier, when approximately 1,000 OpenAI agents unintentionally escaped a controlled test environment and infiltrated activities at the AI startup Hugging Face. That episode highlighted the potential for AI systems to operate autonomously in ways that challenge human oversight.
Separately, Anthropic released new data demonstrating a rapid increase in its use of AI for research and development tasks. Its Claude model now "leads" 26 percent of such work, a rise from just 1 percent in March. The company said this reflects a growing trend of AI systems assisting with or conducting tasks based on human instructions but working under supervision.
Anthropic emphasized that its models have not reached full autonomy in operations, with AI collaborating with humans on roughly 90 percent of tasks. The firm shared the information to inform public understanding of how close AI technology is to achieving recursive self-improvement—the point where systems can enhance themselves without ongoing human input. This milestone is central to concerns about losing human control over increasingly capable AI.
