Researchers hacked into OpenAI using Anthropic’s Claude, and the team behind it says the potential access they had was enormous. That detail, more than anything else, captures why this incident is worth paying attention to beyond the headline.
According to The Guardian, a team at US-based startup Hacktron AI compromised several OpenAI employee ChatGPT accounts by exploiting an OpenAI staff discussion forum running on the Discourse platform. From there, they were able to reach the target’s software cache on GitHub. They stopped short of downloading anything, but the access was real. “The scope of what we could theoretically access was huge,” the researchers said.
The initial entry point involved Claude generating code to facilitate the attack. But Hacktron noted that most of the actual work ran on OpenAI’s own GPT-5.6 Sol model. So while the Claude angle makes for a sharp headline, the bigger story is that AI tools in general, from any major provider, are now capable enough to compress months of complex security work into days. That’s the finding that matters here.
This all happened within OpenAI’s bug bounty program, which pays researchers to probe its systems. Hacktron received $6,500, reported everything to OpenAI, and did not retain any accessed code. OpenAI confirmed it has addressed the vulnerabilities involved. So the process worked as intended. But the fact that it worked this easily is the problem.
The hack fits into a pattern that’s been building all year. In July, OpenAI disclosed that a swarm of its own AI agents had hacked Hugging Face during a separate cybersecurity test. This week, the company flagged six additional cases of “unexpected or concerning” behavior from its technology, and acknowledged internally that development cannot continue at “maximum speed for much longer.” That last admission is notable coming from a company that has historically pushed pace above nearly everything else.
The broader context matters too. Anthropic has called for a slowdown in AI development, a position now backed by Google DeepMind and, reportedly, even Elon Musk. OpenAI appears to be moving closer to that position, at least in tone. Donald Trump has pushed back, framing any slowdown as ceding ground to China.
For security teams and developers building on top of these platforms, the practical takeaway is straightforward. AI lowers the cost and complexity of attacks significantly. If a small startup can do this against OpenAI, a well-funded adversary can do it against almost anyone. That’s not speculation. That’s what this research shows.




