Claude Opus 5 used to breach OpenAI's internal systems in under 72 hours
Three researchers exploited a Discourse bug with Anthropic's AI to access OpenAI employee accounts and source code, earning a $6,500 bounty.
Part of a larger narrative
The AI Control Crisis
- OpenAI agent breached Australian Medicare portal, PM says company took three months to disclose
- Bessent Says OpenAI Managers, Not AI Agents, Are to Blame for Hugging Face Hack
- Consumers sue OpenAI, Anthropic, Google, SpaceXAI for alleged AI development collusion
- Claude Opus 5 used to breach OpenAI's internal systems in under 72 hoursyou are here
- OpenAI forms independent advisory group on mathematics and AI
What to know
- Three Hacktron AI researchers exploited a Discourse image-processing vulnerability with Claude Opus 5 to breach OpenAI's internal systems, gaining access to employee accounts and the company's core algorithmic repository (Monorepo) in under 72 hours.
- The breach demonstrates how advanced AI models have lowered the barrier to sophisticated cyberattacks—Opus 5 succeeded where Opus 4.8 failed, and the team obtained nearly unrestricted access with only basic AI subscriptions.
- OpenAI awarded a $6,500 bug bounty for the breach despite the attackers gaining write access to critical source code, raising questions about whether the reward reflects the actual security risk.
- The incident highlights vulnerabilities in both third-party services (Discourse) and OpenAI's own authentication practices (overly permissive tokens), issues the company says it has now resolved.
The dispute Whether the $6,500 bounty is proportionate to the actual security risk and impact of having achieved write access to OpenAI's core source repository. · positions read across 13 posts and comments
The bounty is absurdly low given the severity of write access to source code.
-
“opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol”
@hailey.at · Bluesky ↗
This is a stark demonstration that AI has made sophisticated cyberattacks accessible to small teams without elite expertise.
-
“The attack shows how newer AI models can cut the time and expertise needed to exploit security flaws.”
The Decoder · The Decoder ↗
Nation-states now have a realistic chance of stealing U.S. AI secrets given how easily this breach occurred.
-
“At a time when the US is engaged in a race with China for AI supremacy, the researchers who hacked OpenAI said the attack suggests that advanced cyber-savvy teams backed by nation-states have a very real chance of getting a peek at the…”
Metacurity (paraphrasing Hacktron AI) · Metacurity ↗
Mohan Pedhapati Chief Technology Officer, Hacktron AIHacktron AI Security research firmOpenAI AI company attackedAnthropic AI company whose Claude was used in breach
How it unfolded 3 developments, newest first · click a bar or a number to jump articlesvideosposts
-
3
Security experts note AI has lowered the barrier to sophisticated exploits
Coverage highlights how Claude Opus 5 succeeded where Opus 4.8 failed, demonstrating that newer AI models dramatically cut the time and expertise needed to discover and exploit security flaws. Researchers achieved full breach in under 72 hours.
“Three security researchers used Anthropic's Claude models to break into OpenAI's internal systems through its community forum in less than 72 hours.”
— The Decoder, Tech news outlet · source -
first by Channel News Asia, 5d ago · also Ars Technica, Ars OpenForum, The Verge, ZeroHedge, The Decoder, The New Stack +4
9 more headlines
- Researchers used Claude to hack OpenAI Ars Technica · 5d ago
- Security researchers used Claude to help them hack into OpenAI The Verge · 5d ago
- Researchers Used Claude To Hack OpenAI Employee Accounts ZeroHedge · 5d ago
- Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours The Decoder · 5d ago
- Claude couldn’t hack OpenAI. Then Anthropic shipped Opus 5. The New Stack · 5d ago
- Researchers used Claude to hack OpenAI employees' ChatGPT accounts The Register · 5d ago
- OpenAI Hack In Under 72 Hours: How 3 Indian-Origin Researchers Used Claude NDTV · 5d ago
- OpenAI hack: How 3 Indian-origin researchers used Anthropic’s Claude to access employee accounts The Indian Express · 5d ago
- OpenAI hack: 3 Indian-origin researchers used Anthropic’s Claude to breach systems Indian Express · 5d ago
-
M
techcrunch.com/2026/09/18/r... Independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses.
2 more of the top 3 · 10 posts in this stretch
-
P
Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earn $6,500 Bug Bounty https:// hackread.com/cybersecurity-sta rtup-claude-ai-hack-openai-bug-bounty/
-
K
Investigadores usaron Claude de Anthropic para hackear OpenAI —
-
-
2
OpenAI confirms breach and patches both vulnerabilities
OpenAI acknowledged two security issues—one in Discourse and another in OpenAI's own systems—and stated both are now resolved. The company narrowed permissions on community sign-in tokens and revoked affected sessions.
“We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
— OpenAI -
H
A three-person cybersecurity team used Anthropic’s Claude to help hack OpenAI during authorized research, taking over employee accounts and reaching an internal code repository in under 72 hours. The reward? A $6,500 bug bounty. Listen/Read: https:// hackread.com/cybersecurity-sta rtup-claude-ai-hack-openai-bug-bounty/ # Cybersecurity # OpenAI #…
-
-
1
Wall Street Journal and news outlets disclose the breach
Hacktron AI disclosed their findings for the first time to the Wall Street Journal. Coverage describes how the researchers breached OpenAI's internal systems using Claude, accessed the company's prized "Monorepo" source code repository, and received a $6,500 bounty from OpenAI's bug bounty program.
“I don't think we are as strong as Chinese threat actors. We're just three guys with Claude and Codex subscriptions.”
— Mohan Pedhapati -
first by Fortune, 5d ago
-
first by The Coin Republic, 5d ago
-
@
Team using Anthropic's Claude hacked into OpenAI's internal code repository. Claude Opus 5 exploited a bug in libheif, an image library used by Discourse, OpenAI's forum host. The stolen login tokens also worked on ChatGPT, including employees' accounts. Reward: a $6,500 bug bounty. …
1 more of the top 2 · 2 posts in this stretch
-
opus 5 was able to assist with breaking into openai — paying a bounty of 6.5k is wild when you just got pwned with write access lol —
-
-
background
Researchers access OpenAI employee tokens and GitHub repository — Using the exploit, the team gained access to authentication tokens from OpenAI's Discourse forum, which were valid on ChatGPT and GitHub. They took over an employee account with Codex access connected to OpenAI's internal monorepo and demonstrated impact by initiating a pull request without accessing sensitive data.
-
background
Anthropic releases Claude Opus 5; exploit succeeds — Initial exploit attempts with Opus 4.8 failed. When Anthropic released Opus 5, Claude quickly found a way to successfully exploit the Discourse vulnerability in the image library, producing working attack code.
-
background
Hacktron AI researchers discover Discourse bug in OpenAI forum — Researchers identified a security flaw in how the Discourse community forum processed certain image files. They accessed a special version of Claude Opus 4.8 to begin developing exploit code.
Also covered reported alongside — the timeline has no entry for these yet
-
4 outlets OpenAI and Anthropic oversold AI security breaches to pressure feds into protecting turf: insiders
first by New York Post, 4d ago · also HN Frontpage, Inshorts, NY Post
2 more headlines
-
first by Gizmodo, 5d ago · also Metacurity
1 more headline
- Three guys used Claude and Codex to hack into OpenAI Metacurity · 5d ago
and 7 smaller pieces
What people are saying 1 voices from 1 site · best of 13 · verbatim
- Sep 19
-
T
Researchers used 3Claude to hack #OpenAI https://arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/ #cbersecurity #AI
