International Edition
Latest News
Technology

Researchers Use Anthropic’s Claude to Hack OpenAI Employee ChatGPT Accounts

In late July 2026, security researchers from Hacktron AI used Anthropic's Claude artificial intelligence model to exploit a vulnerability chain affecting OpenAI's ecosystem, successfully compromising employee ChatGPT and Codex accounts within 72 hours. According to reports published by…

Researchers Use Anthropic’s Claude to Hack OpenAI Employee ChatGPT Accounts

In late July 2026, security researchers from Hacktron AI used Anthropic’s Claude artificial intelligence model to exploit a vulnerability chain affecting OpenAI’s ecosystem, successfully compromising employee ChatGPT and Codex accounts within 72 hours. According to reports published by Hacktron AI and confirmed by OpenAI to Agence France-Presse (AFP), the intrusion took place as part of an authorized security exercise designed to identify system vulnerabilities.

The Vulnerability Chain Starting on the OpenAI Community Forum

The attack vector originated on community.openai.com, OpenAI’s community forum powered by Discourse software, as detailed in disclosures by Hacktron AI. Researchers identified a weakness in how the system handled HEIC and HEIF image files through the libheif processing library. By crafting a malicious image file, the team achieved remote code execution on the forum environment and secured administrative access to OpenAI’s Discourse instance.

From that initial foothold, researchers targeted the forum’s single sign-on feature, which permitted logins via OpenAI credentials. By combining the Discourse remote code execution with flaws in the authentication pipeline, the three-person Hacktron AI team gained control over multiple employee ChatGPT and Codex accounts.

According to Hacktron AI, the multi-step attack progression moved from a malicious image to a compromised forum, exploited authentication weaknesses, and ultimately breached employee accounts. Because those accounts maintained authorizations for connected developer and enterprise tools, the team demonstrated potential access to internal repositories, including prompting a Codex instance to create a pull request on an internal GitHub repository without downloading confidential source code.

Role of Anthropic’s Claude in Accelerating the Exploit

The research highlighted the technical capabilities of modern artificial intelligence models in cybersecurity tasks. Hacktron AI initiated their work using Anthropic’s Claude Opus 4.8 model released in May, but reported that the model struggled to locate an entry point within Discourse.

Researchers Use Anthropic's Claude to Hack OpenAI Employee ChatGPT Accounts
Photo: europe1.fr

The timeline shifted when Anthropic released the Claude Opus 5 model. According to the researchers, the newer iteration identified and developed a working memory corruption exploit for libheif within three hours. The research team directed the investigations and tested the results, utilizing Claude to compress complex exploit development tasks into a fraction of standard timeframes.

Following the discovery, Hacktron AI notified OpenAI and Discourse. OpenAI deployed patches addressing its systems roughly 14 hours after notification, according to Hacktron AI’s timeline. On September 1, 2026, OpenAI awarded the researchers a 6,500 dollar bug bounty reward for the vulnerability.

Industry Context and Security Implications

The incident arrives amid heightened scrutiny surrounding generative artificial intelligence and software security. In April, Anthropic restricted broad commercial availability of its Mythos model due to cybersecurity risks, limiting access to select organizations for defensive auditing. Anthropic subsequently launched a restricted version named Fable in June, which faced a brief national security suspension by the United States government before receiving clearance two weeks later.

Researchers Use Anthropic's Claude to Hack OpenAI Employee ChatGPT Accounts
Photo: 20minutes.fr

OpenAI acknowledged the findings to AFP, with a company spokesperson stating, “We thank the researchers for having contacted us and having shared their observations.” Hacktron AI confirmed they voluntarily limited their access and did not execute mass data exfiltration of user conversations.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”