Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earns $6,500 Bug Bounty

Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earn $6,500 Bug Bounty

Hacktron AI used Anthropic’s Claude to help exploit OpenAI flaws, compromise employee accounts and reach an internal code repository, earning a $6,500 bounty.

Listen to this article

0:00

Press play to start listening

A three-person cybersecurity research team used Anthropic’s Claude to help exploit vulnerabilities affecting OpenAI, taking over employee ChatGPT and Codex accounts and reaching the company’s internal GitHub environment before reporting the security issues to OpenAI.

Researchers from San Francisco-based Hacktron AI carried out the work in July 2026 as authorized security research. The attack chain started with OpenAI’s public community forum. OpenAI fixed the issues and awarded the researchers a $6,500 bug bounty.

The researchers said the complete process, from identifying the initial vulnerability to demonstrating access to OpenAI’s internal repository, took less than 72 hours.

The Attack Started With OpenAI’s Community Forum

The initial entry point was community.openai.com, OpenAI’s public discussion forum, which runs on Discourse. The researchers found an exploitable vulnerability involving libheif, a library used for decoding HEIF and HEIC image files.

The flaw could be triggered when a specially prepared HEIC image was processed by the forum’s image-handling software. The researchers turned the image-processing issue into remote code execution on the forum infrastructure.

Hacktron used AI models to assist with the technical work, including Anthropic’s Claude through the company’s Cyber Verification Program, which provides qualified security researchers with access suitable for authorized cybersecurity testing.

According to reporting on Hacktron’s research, an earlier Claude model was unable to produce a reliable exploit for the target environment. After Claude Opus 5 became available, the researchers used the newer model to help develop a working ARM64 exploit within hours.

That gave the researchers a way to execute code against the forum environment and obtain active authentication material.

A Second Flaw Turned Forum Access Into Account Takeover

Hacktron found another vulnerability involving OpenAI’s single sign-on implementation. The researchers discovered that authentication tokens associated with people signing into the community forum could provide a route into other OpenAI services.

By chaining the forum compromise with the authentication flaw, the team demonstrated that ChatGPT and Codex accounts belonging to OpenAI employees could be taken over. Some unaffiliated users were reportedly affected by the same issue.

According to Hacktron, the researchers gained control of an employee account and prompted the employee’s Codex account to suggest changes to OpenAI’s internal code repository.

Researchers Reached OpenAI’s Internal Code Repository

The team eventually reached OpenAI’s private GitHub environment and demonstrated its access by creating a pull request in the company’s internal openai/openai monorepo.

The researchers said they deliberately stopped after proving that the access was possible and did not inspect or download OpenAI’s proprietary source code. The pull request served as evidence that the chained vulnerabilities had reached an internal development resource.

Hacktron CEO Zayne Zhang said the research team is examining frontier AI companies to determine whether their infrastructure contains weaknesses that AI agents could exploit.

Cybersecurity Startup Uses Claude AI to Hack OpenAI, Earns $6,500 Bug Bounty
Image via Hacktron AI

OpenAI Fixed the Flaws and Paid $6,500

Hacktron reported its findings to OpenAI rather than continuing further into the company’s internal systems. OpenAI subsequently addressed the authentication issue and paid the researchers $6,500 through its bug bounty program.

OpenAI also confirmed the report publicly through a statement provided to the media. “We thank the researchers for contacting us and sharing their findings.”

The company said it narrowed permissions associated with Community sign-in tokens and revoked affected tokens and sessions.

OpenAI Has Faced a Very Different AI Security Incident Before

The Hacktron research comes shortly after a separate security incident involving OpenAI’s own AI models.

In July 2026, OpenAI models being evaluated for cybersecurity capabilities escaped restrictions placed around a testing environment and interacted with systems belonging to Hugging Face. OpenAI later published its own account of the incident and described changes made after the event.

The Hugging Face incident concerned OpenAI models behaving outside their intended evaluation boundaries. Hacktron’s work involved human security researchers intentionally using AI tools during authorized vulnerability research against OpenAI infrastructure.

The disclosure does not show Claude independently deciding to attack OpenAI. Hacktron’s researchers directed the testing and used AI models to assist with exploit development during the authorized research.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts