Researchers exploit Anthropic’s Claude to breach OpenAI
anthropic claude openai
| Source: TechCrunch | Original article
Security researchers leveraged Anthropic’s Claude to exploit OpenAI vulnerabilities, compromising employee accounts and accessing an internal code repository before reporting the flaws.
Security researchers have demonstrated that Anthropic’s Claude language model can be turned into a hacking tool, using it to breach OpenAI’s internal systems. A trio of independent investigators employed Claude’s Opus 4.8 and Opus 5 variants to exploit a flaw in OpenAI’s Discourse community forum, hijacking employee ChatGPT accounts and pulling down code from a private GitHub repository. The team completed the intrusion in under 72 hours and then disclosed the vulnerabilities to OpenAI through its bug‑bounty program.
The episode matters because it shows how generative AI can accelerate the exploitation of software weaknesses. By prompting Claude to generate payloads that bypass a “common security measure,” the researchers reduced the technical expertise and time normally required for such attacks. The breach gave them access to internal code, raising concerns about the confidentiality of proprietary models and the integrity of development pipelines. It also underscores a growing attack surface: AI‑powered assistants embedded in internal tools, forums, or support channels can be co‑opted to automate reconnaissance and privilege escalation.
OpenAI’s next steps will be watched closely. The company is expected to patch the Discourse vulnerability, tighten authentication for employee accounts, and possibly revise how AI assistants are permitted to interact with internal systems. Anthropic may also respond with usage‑policy updates for Claude, especially around “red‑team” or security‑testing scenarios. Regulators and industry groups are likely to cite the incident when drafting guidelines for AI safety and supply‑chain security. As we reported on 18 September, OpenAI has already faced a separate bug‑bounty breach of its monorepo; this new Claude‑driven attack adds urgency to the call for stronger safeguards across the AI ecosystem.
Sources
Back to AIPULSEN