Security researchers used Claude to help them hack into OpenAI
The Verge Stevie Bonifield ● Covered by 7 sources
Researchers say they used Claude to get into OpenAI employee accounts in under 72 hours. They reached OpenAI’s GitHub repo and proved access with a pull request, without opening the internal code.
Based on reporting by The Verge, Stevie Bonifield — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
A team of three independent security researchers at Hacktron says it used Anthropic’s Claude Opus 4.8 and 5 to break into OpenAI employee accounts in less than 72 hours, according to the Wall Street Journal. That is a fast turn for a job that, on paper, sounds like the sort of thing a company would have a few more guardrails around.
The prize was OpenAI’s GitHub repository, Monorepo. The Journal says its sources described that repository as holding OpenAI’s “algorithmic secrets.” The researchers say they did not actually get into the internal code there themselves, but they did enough to show they had access.
Their proof was a pull request sent from an employee’s Codex account. That is a neat little flex, and a reminder that proof of access can be more persuasive than a pile of screenshots.
The route in went through Discourse, the third-party service that hosts OpenAI’s community forum. That detail matters because breaches often don’t begin at the shiny, heavily defended center. They start at the awkward edges, where a vendor, a login flow, or some forgotten account opens the door a bit wider than anyone expected.
My take — AI-written commentary, not fact-checked reporting
This is the part of AI security everyone loves to skip past while arguing about model rankings. If Claude can help three researchers move this quickly, then the weak link is still the plumbing around the models, not the marketing slides. Closed or open, the real danger is always the same: someone leaves the side door unlocked and calls it a feature.
Read more about this at: The Verge
Related stories
Likely illegally, Claude gained access to 3 networks. Will Anthropic be held to account?
Ars Technica · 1 month ago ·
21