Security researchers use Claude to breach OpenAI
anthropic claude openai
| Source: The Verge | Original article
Three independent security researchers at Hacktron used Anthropic’s Claude Opus 4.8 and 5 to breach OpenAI employee accounts and access its Monorepo GitHub repository in under 72 hours.
As we reported on September 19, 2026, a trio of independent security researchers operating under the name Hacktron demonstrated that Anthropic’s Claude language model can be weaponised to breach a rival AI firm. In a new disclosure, the team revealed that they leveraged Claude Opus 4.8 and 5 to compromise OpenAI employee accounts in under 72 hours, ultimately gaining read‑only access to the company’s internal GitHub “Monorepo” codebase.
The attack hinged on a corrupted image file and a flaw in OpenAI’s Discourse‑based forum software. By prompting Claude to generate exploit payloads, the researchers were able to bypass multi‑factor authentication, hijack employee credentials and navigate to the private repository. The breach was reported to OpenAI before any public exploitation occurred.
The episode underscores a growing security paradox: the very models marketed as productivity boosters are also becoming powerful tools for adversaries. Claude’s ability to synthesize functional code and adapt to novel attack vectors demonstrates that large language models can accelerate the discovery and automation of vulnerabilities, raising the stakes for all organisations that rely on them.
Watch for OpenAI’s response, including any patches to the Discourse integration and revisions to credential‑management policies. Anthropic is expected to comment on the misuse of Claude and may tighten usage controls or introduce safeguards against malicious prompting. The incident also revives broader industry debate on responsible AI deployment and the need for dedicated AI‑focused security assessments, a theme explored in our earlier coverage of AI‑related threat actors.
Sources
Back to AIPULSEN