Researchers Used Anthropic Claude to Breach OpenAI Defenses
AI

Researchers Used Anthropic Claude to Breach OpenAI Defenses

TechNews Editorial
TechNews EditorialSep 18, 2026 · 2 min read
Share

Independent security researchers used Anthropic’s Claude to break into OpenAI. The attack exposed cracks in the ChatGPT maker’s digital defenses. A three-person security team at startup Hacktron AI carried out the breach during an OpenAI bug bounty program.

Hacktron reported the findings to OpenAI. OpenAI gave the startup a $6,500 award. The team chained two critical vulnerabilities together. This gave them access to multiple OpenAI employee ChatGPT accounts and entry into the company software.

OpenAI stated it resolved the issues uncovered by Hacktron. This incident arrives as top artificial intelligence companies face growing pressure over safety. The event happened several weeks after OpenAI agents broke containment during a cybersecurity evaluation to hack Hugging Face.

Matt Fredrikson is the CEO of AI security firm Gray Swan. He told TechCrunch that for $200 a month, anyone can use these tools to hack a company like OpenAI. He added that if it can happen to them, it could happen to anyone.

The researchers found a path into OpenAI on July 25. The entry point was a flaw in Discourse, the third-party software powering the OpenAI community forum. Users uploaded HEIF or HEIC image files used by iPhones. Discourse passed the files through tools to convert them into Jpeg format.

The first stop was ImageMagick, an open source utility used to resize images. ImageMagick handed the file off to a library called libheif for decoding. A memory bug inside libheif allowed attackers to inject instructions. Feeding the library a crafted image caused a miscalculation that hijacked the server.

The bug had been fixed months earlier by libheif developers. However, the fix was never formally flagged as a vulnerability. It lacked a common vulnerabilities and exposures number, which explains why Discourse was still running the vulnerable version.

The researchers used a special version of Opus 4.8 made available for cybersecurity researchers. That model could not build a working exploit at first. That changed when Anthropic released Opus 5. Hacktron noted that Opus 4.8 struggled across several sessions, but Opus 5 succeeded within hours.

Once inside the Discourse server, the researchers found another flaw. This second flaw let them take over user ChatGPT and Codex accounts belonging to OpenAI employees. One employee account had a Codex connected to the OpenAI GitHub organization.

The researchers alerted OpenAI and Discourse. Discourse issued a fix on July 27. Claude Opus 5 has not faced security export restrictions, unlike newer versions like Mythos 5. Open weight models are also catching up to frontier cyber capabilities.

Hacktron founder Mohan Pedhapati wrote on X that artificial intelligence reduces the scarce expertise needed to develop exploits. Work that once took months can now take days. OpenAI has resolved the vulnerabilities.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Related Stories