Ethical Hackers Used Claude to Breach OpenAI Employee Accounts
Security researchers exploited AI chatbots to access ChatGPT accounts and reach OpenAI's private code repository through a bug bounty program.

Security researchers breach OpenAI systems with AI assistance
A U.S.-based security research team successfully compromised OpenAI employee systems by weaponizing AI chatbots, including Anthropic's Claude, to gain access to internal accounts and a restricted code repository.
Hacktron AI, working under OpenAI's bug bounty program, initiated the operation through an employee discussion forum hosted on the Discourse platform. The researchers used Claude to compromise ChatGPT accounts belonging to OpenAI staff members. From there, they escalated access by submitting a pull request—a proposed code modification—to OpenAI's GitHub repository, according to reporting by The Guardian.
The team described the potential scope of their access as "huge," though they emphasized they did not actually download any files from the repository. While Claude helped launch the operation, the researchers relied primarily on OpenAI's own GPT-5.6 Sol model to execute most of the work.
Why it matters
This incident demonstrates a troubling reality for cybersecurity: AI tools are dramatically compressing the timeline for sophisticated attacks. Operations that previously required months of effort from well-resourced teams can now be executed in days with AI assistance. As organizations rush to deploy AI capabilities, they're simultaneously arming potential attackers with the same productivity gains—a dynamic that fundamentally reshapes the security landscape for every company managing sensitive systems.
OpenAI patches vulnerabilities, pays bounty
OpenAI compensated Hacktron AI with $6,500 through its bug bounty program, which incentivizes ethical hackers to identify and report security weaknesses before malicious actors can exploit them. The company confirmed it has since patched the security gaps the researchers identified.
"We thank the researchers for contacting us and sharing their findings," an OpenAI spokesperson stated.
According to a September 2026 update, the two vulnerabilities Hacktron AI exploited were previously unknown zero-day flaws. No evidence suggests other hackers discovered or exploited these same weaknesses.
AI-accelerated security threats
The researchers' observation about AI-compressed attack timelines reflects a broader shift in cybersecurity. The same generative AI tools that promise productivity gains for legitimate users also lower barriers for attackers, enabling faster reconnaissance, more sophisticated social engineering, and accelerated exploitation of discovered vulnerabilities.
For organizations deploying AI systems, the incident underscores the need to consider not just how AI improves their own operations, but how it might be turned against their infrastructure by adversaries equipped with identical capabilities.
These details were first reported by The Wall Street Journal and subsequently covered by The Guardian.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call