Researchers used Claude to breach OpenAI's internal systems

Published
0
People visit an OpenAI booth at Moscone Center during the Dreamforce 2026 technology summit in San Francisco, California, US on September 17, 2026. —Reuters
People visit an OpenAI booth at Moscone Center during the Dreamforce 2026 technology summit in San Francisco, California, US on September 17, 2026. —Reuters

A security research company said Friday it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.

The researchers from security firm Hacktron said they found a security flaw in OpenAI’s public help forum, run by the Discourse platform, that allowed them to take control of the site.

“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch,” Hacktron said in a blog post.

“We appreciate their attention to detail and fast resolution of this issue,” the post added.

OpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a $6,500 reward.

“We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” said Drew Pusateri, an OpenAI spokesperson.

The Hacktron researchers said they initially used Anthropic’s Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently.

After Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours.

The hackers did not use Claude Mythos, a more capable Anthropic model that is restricted to a small group of vetted cyber-defence organisations.

Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built.

Hacktron said the underlying software flaw is not unique to OpenAI and is used across many companies’ products, including those made by Slack and Meta.

The firm said it is continuing similar tests at other companies.

The case adds to growing concern among security experts that AI tools are making it faster and cheaper to carry out sophisticated cyberattacks that once required specialised teams and months of work.

Opinion

Editorial

Kashmir unresolved
Updated 30 Sep, 2026

Kashmir unresolved

The just solution lies in India addressing the issue through a trilateral dialogue involving the legitimate representatives of the Kashmiri people and Pakistan.
Water shortage
30 Sep, 2026

Water shortage

THAT the country is entering the Rabi season with an anticipated water shortage of nearly 25pc, the lowest carryover...
Young hearts
30 Sep, 2026

Young hearts

THE observance may have passed, but the message of World Heart Day should not fade with it. The occasion is a useful...
Terror and politics
Updated 29 Sep, 2026

Terror and politics

There is an urgent need to tone down the rhetoric and tackle terrorism as a collective challenge for both the affected provinces and the federation.
Watching the glaciers
29 Sep, 2026

Watching the glaciers

THE latest signs from Pakistan’s mountains are worrying. Suparco says the number of unfrozen glacial lakes it...
Dangerous agenda
29 Sep, 2026

Dangerous agenda

AS the world remains fixated on the US-Iran conflict, elsewhere in the Middle East, Israel is consolidating its grip...