Security researchers exploit Claude to hack OpenAI and get paid
agents anthropic claude openai
| Source: Digital Trends | Original article
Security researchers leveraged Anthropic’s Claude to exploit a Discourse flaw, gaining access to OpenAI employee ChatGPT accounts and earning a bug bounty.
Security researchers have demonstrated that Anthropic’s Claude can be weaponised as an attack tool. By leveraging a vulnerability in Discourse—the forum software that powers OpenAI’s community site—the team used Claude to bypass authentication and obtain access to employee ChatGPT accounts. Within 72 hours they escalated the breach to OpenAI’s private code repository, where they submitted a “harmless” pull request as proof of concept before alerting the company. OpenAI patched the flaw within 14 hours and rewarded the researchers with a $6,500 bounty through its Bugcrowd program, equivalent to roughly ₹6.27 lakh.
The incident underscores a shifting threat landscape in which sophisticated language models are no longer just targets but also vectors for exploitation. Claude’s ability to parse code, generate payloads and automate reconnaissance allowed the researchers to move from a public‑facing forum flaw to internal systems with unprecedented speed. As AI agents become more capable of autonomous reasoning and tool use, they lower the technical barrier for attackers and expand the attack surface of organisations that integrate such models into their workflows.
Going forward, the episode is likely to prompt tighter scrutiny of third‑party platforms that interface with AI services and may accelerate the adoption of stricter AI‑specific security standards. Companies that expose internal tools to external AI agents could face new compliance requirements, while bug‑bounty programs may see a rise in submissions that involve AI‑generated exploits. Observers will watch how OpenAI and Anthropic respond—whether through hardening of integration points, updated disclosure policies, or collaborative efforts to develop defensive AI capabilities. The case also adds urgency to broader industry discussions about responsible AI deployment and the need for coordinated safeguards against AI‑enabled cyber threats.
Sources
Back to AIPULSEN