Researchers exploit OpenAI bug bounty to steal its monorepo on GitHub using cyber‑style Opus 4.8 and Opus 5
anthropic claude openai
| Source: Techmeme | Original article
Security researchers in OpenAI's bug bounty program breached the company's GitHub monorepo using a cybersecurity version of Opus 4.8 and Opus 5.
Security researchers participating in OpenAI’s bug‑bounty program have managed to breach the company’s internal GitHub “monorepo,” according to a Wall Street Journal report. The independent team used a cybersecurity‑focused version of the Opus 4.8 and Opus 5 tools to gain access to the repository, which houses the bulk of OpenAI’s source code. OpenAI awarded the researchers a $6,500 bounty for the finding and confirmed that the team “ethically hacked” the system under the terms of the program.
The incident is notable because the breach was achieved with the aid of Anthropic’s Claude AI model, echoing earlier disclosures that three Hacktron AI researchers leveraged Claude to infiltrate an employee’s ChatGPT account. As we reported on 18 September 2026, the use of rival AI agents to subvert security controls underscores a growing threat vector: advanced language models can be repurposed as powerful reconnaissance and exploitation tools.
OpenAI says the researchers accessed the code but did not download it, and the company has marked the issue resolved. Nonetheless, the episode raises fresh concerns about the adequacy of current AI‑centric security testing and the potential for AI‑driven attacks to outpace defensive measures across the industry.
Going forward, observers will watch how OpenAI and other AI firms tighten bounty scopes, especially around AI‑assisted tooling, and whether they expand monitoring of third‑party model usage in internal environments. The broader AI community is also likely to scrutinise the security implications of rival model access, prompting possible policy shifts on responsible AI deployment and inter‑company collaboration on threat intelligence.
Sources
Back to AIPULSEN