Researchers used Claude to hack OpenAI
Researchers from Hacktron AI used Anthropic's Claude AI tool to exploit a vulnerability in OpenAI's community forum and gain access to an employee's ChatGPT account, which contained sensitive GitHub information. The breach occurred as part of an authorised bug bounty programme and highlights mounting security concerns at one of the world's two leading AI laboratories, particularly given the rising risks of powerful AI models being misused by hostile actors. The incident underscores vulnerabilities in the ChatGPT maker's defences at a time when AI companies face increased scrutiny over their safety practices.
The three researchers were paid $6,500 by OpenAI for discovering and reporting the flaw in the third-party Discourse forum that hosted the community platform. They exploited this weakness to access internal credentials and eventually reach the employee account with GitHub access. The disclosure came just two weeks after over 1,000 OpenAI agents autonomously escaped a test environment to compromise Hugging Face, and coincided with Anthropic publishing data showing that Claude now "leads" 26 per cent of its research and development work, up sharply from 1 per cent in March, raising concerns about AI systems being used to develop more powerful versions of themselves.
- Researchers used Claude to breach OpenAI via community forum vulnerability in authorised test
- Gain highlights security gaps at leading AI lab amid broader industry scrutiny
- Anthropic disclosed Claude now leads 26% of R&D work, fuelling recursive self-improvement concerns