
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Cybersecurity researchers at Hacktron AI used Anthropic’s Claude to breach OpenAI systems and access an employee’s ChatGPT account, which then provided access to internal code stored on GitHub.
Summary
The incident was carried out under OpenAI’s bug bounty programme, with the company paying the researchers USD 6,500 after they disclosed the vulnerabilities. The research highlights how AI tools are making complex cybersecurity work faster. It also shows how an AI model can help researchers identify and exploit flaws that could expose access to sensitive systems.
Claude Helped Build The Exploit The researchers first tested Anthropic’s Claude Opus 4.8. They said the model struggled across several sessions to produce a working exploit. The team succeeded after Anthropic released Claude Opus 5.
The researchers noted that “every new model is getting increasingly capable.” According to the report, the researchers had access to a special version of Claude available to qualified cybersecurity practitioners. They said the OpenAI breach took a few days for an AI agent and only a few hours of human work. The effort was part of a wider research project called “HEIF Heist”.
The project focused on vulnerabilities linked to the way software processes certain image files. The researchers said the wider project also uncovered flaws involving Slack, Zoom and Meta. It involved three researchers and lasted two months.
The team said it spent less than USD 3,000 on AI tokens during the project. OpenAI Fixed The Vulnerabilities The researchers said the incident showed how AI can reduce the time and resources needed for advanced security research. In their conclusion, they wrote, “Software has long benefited from a kind of security through complexity...
AI is removing that protection by turning more of this scarce expertise into compute. Work that once required a well-resourced team and months of effort can now be compressed into days... Security assumptions must catch up with attacker capabilities.” OpenAI said, “We thank the researchers for contacting us and sharing their findings,” and confirmed that the vulnerabilities had been fixed.
Anthropic declined to comment when approached, while Hacktron did not immediately respond to requests for comment, according to the report. The incident follows another recent case involving OpenAI AI agents and the cybersecurity startup Hugging Face . More than 1,000 OpenAI agents reportedly escaped a test environment and attempted to hack the company’s systems.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 95 other articles touching the same topic (latest news, technology) — see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.