OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot

Read the original at The Guardian ↗
The Guardian · collected 2026-09-18 · by Dan Milmo Global technology editor

Quick Summary

Cybersecurity researchers at Hacktron AI exploited OpenAI’s systems using Anthropic’s Claude chatbot, gaining access to ChatGPT accounts through an OpenAI staff forum. The hack, conducted under OpenAI's ethical hacking program and reported by the Wall Street Journal, resulted in a $6,500 reward for Hacktron. Researchers noted that advanced AI tools like Claude simplified what was once a complex task, reducing planning and execution time significantly.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
15
claim-shaped sentences
Uncertain
13%
2 of 15 hedged
Leaning
Leans right
of the writing, not the subject · beta estimate
Correction & hedging signals
68.3
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads leans right and hedges 13% of its claims. Each row says how that neighbour differs.
NBC News · 0.88 cosine similarity
⚖️ leaning not scored 🔴 11% hedged 2 of 19 📰 publisher trust 95
“Both articles describe the same cybersecurity incident where researchers from Hacktron AI hacked into OpenAI using Anthropic's Claude chatbot and exploiting vulnerabilities in Discourse and OpenAI employee validation.”
CBS News · 0.87 cosine similarity
⚖️ leaning not scored 🔴 12% hedged 2 of 16 📰 publisher trust 66
“Both articles describe a single incident where Hacktron AI used Anthropic's Claude to hack into OpenAI’s ChatGPT accounts, accessing employee data and forum discussions on the same day.”
The Straits Times · 0.86 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 15 📰 publisher trust 59
“Both articles describe the same incident where researchers from Hacktron AI used Anthropic’s Claude chatbot to hack into OpenAI's internal systems via a security flaw on their public help forum.”
September 13, 2026 different event · 95%
Letters from an American
⚖️ Leans left further left than this 🔴 15% hedged 10 of 65
“The articles describe different events - Article A discusses Dario Amodei's essay about AI safety concerns, while Article B reports on a cybersecurity incident involving hacking of OpenAI with the help of Anthropic’s Claude chatbot.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“The articles describe different security incidents involving separate entities exploiting vulnerabilities at OpenAI.”
Dawn
⚖️ leaning not scored 🔴 36% hedged 8 of 22 📰 publisher trust 77
“The articles describe different hacking incidents involving OpenAI and Hugging Face, not the same specific event.”
New York Post
⚖️ leaning not scored 🔴 29% hedged 7 of 24 📰 publisher trust 64
“The articles describe different events related to Anthropic's Claude chatbot: one discusses a warning about its training methods, and the other reports on a cybersecurity incident involving Claude.”
Semafor
⚖️ Centre further left than this 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe researchers using Anthropic's Claude AI to hack into OpenAI’s ChatGPT systems on the same date.”
Dawn
⚖️ leaning not scored 🔴 0% hedged 0 of 14 📰 publisher trust 77
“Both articles describe the same cybersecurity breach of OpenAI's systems using Anthropic’s Claude chatbot, involving the same initial discovery on a Discourse forum and mentioning similar details about access to ChatGPT accounts.”
Times of India
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 59
“Both articles describe a single security incident where researchers used Anthropic’s Claude chatbot to breach OpenAI systems, accessing employee accounts and potentially internal code repositories.”

Publisher

The Guardian · 1277 article(s) · 4 correction(s) detected
Running correction rate · 4 correction(s)
2026-10-03
Tennessee’s top prison official resigning after botched execution of Christa Pike
2026-10-01
Tennessee governor suspends all executions after Christa Pike’s lethal injections fail
2026-09-28
Extra 1,000 prison beds announced in NSW as union warns against arresting ‘our way out of domestic violence’
2026-09-05
Australia’s housing prices are trending down. See which suburbs have had the biggest falls

Who wrote this

Dan Milmo Global technology editor
4 article(s) here · 1 carrying a prediction
🔮 Pornhub’s age checking regime may not be “highly effective”, according to Ofcom, and could be in breach of online safety laws requiring strict measures to prevent under-18s from accessing sexually explicit content.
🔮 Nick Clegg could make approximately $40m (£30m) from the planned float of Nscale as the UK-based datacentre company prepares for a US stock market listing.
🔮 “The scope of what we could theoretically access was huge,” said researchers at Hacktron AI.
🔮 You would expect that they move quickly.
Also by Dan Milmo Global technology editor
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

Anthropic ChatGPT Claude Hacktron OpenAI

Subjects

OpenAI ORG · 11× Hacktron ORG · 3× Anthropic ORG · 2× GitHub ORG · 2× Elon Musk PERSON · 1× Google DeepMind ORG · 1× Hacktron AI ORG · 1× Hugging Face ORG · 1× San Francisco ORG · 1× the Wall Street Journal ORG · 1×

Narrative

An OpenAI spokesperson said: “We thank the researchers for contacting us and sharing their findings”, adding that the company had addressed the vulnerabilities that had been exploited. Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack.
framing: assertive · carried by 1 article(s) · first seen 2026-09-18
🔮 “The scope of what we could theoretically access was huge,” said researchers at Hacktron AI.
2026-09-18 · The Guardian
OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot · assertive framing

Claims (15 extracted, 2 hedged)

Cybersecurity researchers have hacked into OpenAI with the help of Anthropic’s Claude chatbot, in the latest example of security issues at the company. asserted
researchers → hack → company
A team at a US-based startup compromised a number of OpenAI employees’ ChatGPT accounts, starting a process that enabled them to access their target’s software cache – and potentially more. asserted
that → base → cache
“The scope of what we could theoretically access was huge,” said researchers at Hacktron AI. uncertain
researchers → access → AI
Initially, the research team used Claude, which can generate code for hackers, to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform. asserted
which → use → platform
They then made a harmless “pull request” – an attempt to change the code in a file – to OpenAI’s service on the GitHub software repository. asserted
They → make → repository
Hacktron reported the hack to OpenAI, having carried out the operation under an OpenAI programme that rewarded ethical hackers for testing its systems. asserted
that → report → systems
The researchers stressed that they had access to, but did not download, the code from the GitHub repository. asserted
they → stress → repository
Despite initial use of Claude, the researchers said they were largely using OpenAI’s own cutting edge GPT-5.6 Sol model to carry out the hack, which was first reported by the Wall Street Journal. asserted
which → say → Journal
An OpenAI spokesperson said: “We thank the researchers for contacting us and sharing their findings”, adding that the company had addressed the vulnerabilities that had been exploited. Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack. asserted
task → say → attack
This is a common refrain from cybersecurity experts when discussing the impact of AI. asserted
This → discuss → AI
“Work that once required a well-resourced team and months of effort can now be compressed into days,” said Hacktron, which received a $6,500 payment from OpenAI under the company’s bug bounty programme. asserted
which → require → programme
The hack is the latest safety incident at OpenAI, which revealed in July that a “swarm” of agents – the term for AI tools capable of carrying out tasks autonomously – powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test. asserted
swarm → reveal → test
This week the San Francisco-based company revealed six more examples of “unexpected or concerning” actions by its technology, and warned that the pace of development could not continue at “maximum speed for much longer”. Anthropic made a fresh call at the weekend for a slowdown in AI development, which was supported by OpenAI, Google DeepMind and Elon Musk. uncertain
which → base → OpenAI
also repeated warnings that unrestrained AI development posed an existential threat, concerns that some experts are sceptical about. asserted
experts → repeat → that
Donald Trump has rejected calls for a slowdown, citing a need to stay ahead of China’s AI industry and dismissing “negative forces … bringing up things that won’t happen”. asserted
that → reject → things
💬Give feedback
🕘History 🎫Support