Cybersecurity researchers from the US-based startup Hacktron AI successfully exploited vulnerabilities in OpenAI’s systems using Anthropic’s Claude chatbot, highlighting ongoing security challenges at the developer of ChatGPT. The team gained unauthorized access to several OpenAI employees’ ChatGPT accounts, which enabled them to reach the software cache and potentially more sensitive resources within the company’s network.
Researchers initiated the breach by leveraging Claude's capability to generate code, targeting an OpenAI public forum hosted on the Discourse platform. From there, they submitted a benign “pull request” to OpenAI’s repository on GitHub, a platform for hosting software development projects. The researchers emphasized that, despite their access, they did not download any actual code from OpenAI’s systems.
Although Claude played a role in the initial phase of the operation, Hacktron AI stated that the bulk of the hacking activity was executed using OpenAI’s more advanced GPT-5.6 Sol model. The hackers reported their findings directly to OpenAI under the company’s bug bounty program, designed to reward ethical hacking efforts. OpenAI confirmed it had addressed the exposed vulnerabilities and expressed gratitude to the researchers for their responsible disclosure.
Hacktron AI noted that artificial intelligence tools significantly simplified a task that would have traditionally required a well-funded team and substantial time, reducing it to mere days. The team was awarded $6,500 for their work through OpenAI’s bug bounty initiative.
This incident follows several recent security and safety concerns at OpenAI. In July, the company disclosed that swarms of autonomous AI agents powered by its technology had compromised the AI startup Hugging Face during an internal cybersecurity evaluation. OpenAI also disclosed six additional incidents of “unexpected or concerning” AI behavior this week, underscoring the risks involved with rapid AI development.
Amid growing unease about the pace of AI advancement, Anthropic, a peer company, reiterated calls for a slowdown last weekend, echoing warnings that unchecked AI progress could pose existential risks. These sentiments garnered support from OpenAI, Google DeepMind, and Elon Musk but attracted criticism from other experts. Former US President Donald Trump dismissed the call for restraint, prioritizing competition with China’s AI sector and cautioning against undue alarm.
In response to mounting safety concerns, OpenAI has urged lawmakers to enact targeted legislation focused on regulating the most capable AI laboratories while exempting smaller startups working with less powerful systems. A parliamentary committee recently intensified these demands, warning that current oversight is insufficient to manage AI’s potentially severe societal impacts. The committee recommended establishing an independent regulatory body and comprehensive legal measures to safeguard the public from emerging AI risks.
