Researchers used Claude to breach OpenAI’s internal systems

Read the original at The Straits Times ↗
The Straits Times · collected 2026-09-18 · by The Straits Times

Quick Summary

On September 18, researchers from Hacktron used Anthropic’s Claude AI model to identify a security flaw in OpenAI’s public help forum and exploit it within three hours after the release of Claude Opus 5. The breach was reported immediately, and OpenAI fixed the issue within about 14 hours, paying Hacktron $6,500 as part of their bug bounty program. This incident highlights how AI tools are rapidly advancing cyberattack capabilities, making sophisticated attacks easier to execute.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
15
claim-shaped sentences
Uncertain
0%
0 of 15 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
59.1
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 0% of its claims. Each row says how that neighbour differs.
Dawn · 0.98 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 14 📰 publisher trust 77
“Both articles describe the identical incident of researchers from Hacktron using Claude to breach OpenAI's internal systems on the same date.”
CBS News · 0.87 cosine similarity
⚖️ leaning not scored 🔴 12% hedged 2 of 16 📰 publisher trust 66
“Both articles describe researchers using Claude to breach OpenAI's internal systems and access their forums on the same date, September 18, 2026.”
The Guardian · 0.86 cosine similarity
⚖️ Leans right 🔴 13% hedged 2 of 15 📰 publisher trust 68
“Both articles describe the same incident where researchers from Hacktron AI used Anthropic’s Claude chatbot to hack into OpenAI's internal systems via a security flaw on their public help forum.”
September 13, 2026 different event · 95%
Letters from an American
⚖️ Leans left 🔴 15% hedged 10 of 65
“The articles describe different incidents; one is about Dario Amodei's call for slowing AI development, while the other reports on a security breach conducted by researchers using Anthropic's software.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“Article A describes AI agents exploiting vulnerabilities in OpenAI's internal testing environment, while Article B discusses researchers from a security firm breaching OpenAI’s public help forum using software from Anthropic.”
CBS News
⚖️ leaning not scored 🔴 28% hedged 5 of 18 📰 publisher trust 66
“Article A discusses a general warning about potential future AI cyberattacks, while Article B describes a specific breach that occurred on September 18 involving researchers from Hacktron using Claude to access OpenAI's internal systems.”
CBS News
⚖️ leaning not scored 🔴 12% hedged 2 of 17 📰 publisher trust 66
“The articles describe different incidents: one involves unexpected AI behavior from an unreleased model, while the other reports a security breach of OpenAI's internal systems by researchers using Claude.”
Semafor
⚖️ Centre 🔴 50% hedged 2 of 4 📰 publisher trust 95
“Article A discusses internal incidents at OpenAI involving model misbehavior and a trust gap, while Article B reports on an external security breach conducted by researchers using Anthropic's Claude to access OpenAI’s systems.”
Semafor
⚖️ Centre 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe researchers using Anthropic’s Claude AI to break into OpenAI's systems on the same day, September 18, 2026.”
Times of India
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 59
“Both articles describe the same security breach conducted by researchers at Hacktron using Claude AI to exploit OpenAI's systems, reported on the same day.”

Publisher

The Straits Times · 1922 article(s) · 3 correction(s) detected
Running correction rate · 3 correction(s)
2026-10-04
Tennessee prison chief resigns after failed execution
2026-10-03
US prison chief resigns after failed execution of death row inmate Christa Pike
2026-09-13
Russia hits Ukrainian-Polish border area, Kyiv says

Who wrote this

The Straits Times
1327 article(s) here · 0 carrying a prediction
🔮 Dozens of climate lawsuits could live or die by a US Supreme Court case to be heard on Oct 5 seeking damages from oil companies for their role in global warming and for concealing the dangers of fossil fuels.
🔮 Reuters could not immediately verify the report.
🔮 Latitude said it would work with the US National Transportation Safety Board, the Transportation Safety Board of Canada and other authorities on recovery efforts and the investigation into why the plane crashed.
🔮 If Bolsonaro triumphs in the Oct 25 election, the Latin American powerhouse will join a steady rightward march in the region in recent elections, a trend championed by US President Donald Trump.
🔮 She will appear on Oct 5 in a Los Angeles federal court, Essayli said.
🔮 Polls also give the PQ about 30% support, but in the province’s first-past-the-post electoral system that could be enough to secure a majority in the 127-member National Assembly, with the federalist vote expected to split among several parties.
🔮 The winners of the six Nobel prizes for medicine, physics, chemistry, literature, peace and economics will be revealed daily from Oct 5-12.
🔮 Rivet, which opens to US users on Oct 8, relies on a pool of volunteer “matchers” who rate whether two given people might be compatible.
🔮 Paraguay opposition candidate wins Asuncion mayor's race in gauge of 2028 vote ASUNCION, Oct 4 -
🔮 Earlier in 2026, the committee warned that as a result, British public services could be “derailed at any time by a decision taken outside our shores”.
Also by The Straits Times
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 1327 articles by The Straits Times →

Topics

Anthropic Claude Discourse Hacktron OpenAI

Subjects

OpenAI ORG · 6× Anthropic ORG · 4× Hacktron ORG · 4× Claude Opus 4.8 to PERSON · 1× Community ORG · 1× Discourse ORG · 1× Drew Pusateri PERSON · 1× Meta ORG · 1× Slack ORG · 1× WASHINGTON GPE · 1×

Narrative

A security research company said on Sept 18 it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.
framing: assertive · carried by 1 article(s) · first seen 2026-09-18
2026-09-18 · The Straits Times
Researchers used Claude to breach OpenAI’s internal systems · assertive framing

Claims (15 extracted, 0 hedged)

Researchers used Claude to breach OpenAI’s internal systems AI generated asserted
Researchers → use → AI
A security research company said on Sept 18 it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks. asserted
technology → say → cyberattacks
The researchers from security firm Hacktron said they found a security flaw in OpenAI’s public help forum, run by the Discourse platform, that allowed them to take control of the site. asserted
them → say → site
“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch,” Hacktron said in a blog post. asserted
Hacktron → report → post
“We appreciate their attention to detail and fast resolution of this issue,” the post added. asserted
post → appreciate → issue
OpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a US$6,500 (S$8,300) reward. asserted
flaw → confirm → reward
“We thank the researchers for contacting us and sharing their findings. asserted
We → thank → findings
We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” said Drew Pusateri, an OpenAI spokesperson. asserted
Pusateri → narrow → tokens
The Hacktron researchers said they initially used Anthropic’s Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently. asserted
it → say → flaw
After Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours. asserted
model → release → hours
The hackers did not use Claude Mythos, a more capable Anthropic model that is restricted to a small group of vetted cyber-defence organisations. asserted
that → use → organisations
Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built. asserted
it → describe → model
Hacktron said the underlying software flaw is not unique to OpenAI and is used across many companies’ products, including those made by Slack and Meta. asserted
flaw → say → Slack
The firm said it is continuing similar tests at other companies. asserted
it → say → companies
The case adds to growing concern among security experts that AI tools are making it faster and cheaper to carry out sophisticated cyberattacks that once required specialised teams and months of work. asserted
that → add → work
💬Give feedback
🕘History 🎫Support