Researchers used Claude to breach OpenAI's internal systems

Read the original at Dawn ↗
Dawn · collected 2026-09-18 · by AFP

Quick Summary

Security researchers from Hacktron used Anthropic’s language model Claude to exploit a flaw in OpenAI’s public help forum, which they reported on Friday after gaining control within about three hours using the updated Claude Opus 5 model. The vulnerability was fixed by OpenAI within 14 hours and the company paid Hacktron a $6,500 reward for their discovery. This incident highlights how rapidly evolving AI technology can be leveraged to conduct sophisticated cyberattacks efficiently, raising concerns among security experts about the broader implications of such tools.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
14
claim-shaped sentences
Uncertain
0%
0 of 14 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
77.2
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 0% of its claims. Each row says how that neighbour differs.
The Straits Times · 0.98 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 15 📰 publisher trust 59
“Both articles describe the identical incident of researchers from Hacktron using Claude to breach OpenAI's internal systems on the same date.”
Semafor
⚖️ Centre 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe the identical incident of researchers using Anthropic's Claude technology to break into OpenAI’s ChatGPT systems on the same date.”
Times of India
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 59
“Both articles describe the same security breach of OpenAI’s systems using Anthropic's Claude AI, carried out by researchers from Hacktron.”
ABC News (US)
⚖️ leaning not scored 🔴 0% hedged 0 of 16 📰 publisher trust 59
“The articles describe different events: one is about OpenAI disclosing concerning AI behavior, while the other reports a security breach in OpenAI's systems by an external research firm.”
Global News
⚖️ leaning not scored 🔴 7% hedged 2 of 27 📰 publisher trust 64
“The articles describe different security incidents: one involving six reported AI misalignment cases by OpenAI, and another where researchers from Hacktron used Claude to breach OpenAI's internal systems.”
Semafor
⚖️ Centre 🔴 50% hedged 2 of 4 📰 publisher trust 95
“The articles describe different security incidents: one involves OpenAI's models misbehaving, while the other is about researchers from Hacktron breaching OpenAI’s systems using Anthropic's software.”
The Guardian
⚖️ Leans right 🔴 13% hedged 2 of 15 📰 publisher trust 68
“Both articles describe the same cybersecurity breach of OpenAI's systems using Anthropic’s Claude chatbot, involving the same initial discovery on a Discourse forum and mentioning similar details about access to ChatGPT accounts.”
NBC News
⚖️ leaning not scored 🔴 11% hedged 2 of 19 📰 publisher trust 95
“Both articles describe a single breach of OpenAI's internal systems by researchers from Hacktron using vulnerabilities in Discourse and OpenAI’s validation process, reported on different dates.”
CBS News
⚖️ leaning not scored 🔴 28% hedged 5 of 18 📰 publisher trust 66
“Article A discusses general warnings about AI cyberattacks, while Article B reports on a specific breach of OpenAI's systems using Anthropic's technology.”
CBS News
⚖️ leaning not scored 🔴 12% hedged 2 of 16 📰 publisher trust 66
“While both articles report security breaches involving Claude and OpenAI, Article A mentions breaching the internal systems through a public help forum while Article B specifically cites accessing an employee's ChatGPT account and retrieving source code storage information.”

Publisher

Dawn · 1158 article(s) · 2 correction(s) detected
Running correction rate · 2 correction(s)
2026-10-01
Tennessee woman in hospital after execution 'failed': lawyers
2026-09-20
An eye on Balochistan border

Who wrote this

AFP
397 article(s) here · 0 carrying a prediction
🔮 Former Real Madrid and Manchester United striker Ronaldo walked out on the squad on Wednesday, ahead of the previous game against Denmark, after Portugal’s all-time top goalscorer learned he would not start.
🔮 Up to 500 schools across France will be totally or partly closed on Monday (October 5, 2026) because of a wave of student protests that has shaken the country, the Education Minister said.
🔮 Iran’s top diplomat insisted on Sunday that there would be no military solution to the United States’ war against the Islamic republic, with talks on ending the conflict apparently at an impasse.
🔮 The government has said that while the grievances may be legitimate, violence is not and has accused the hard-left of whipping up the movement. Critics have meanwhile accused some police of heavy-handed force against protesters, who are legally still children. More than 5,000 people have been arrested since Monday, according to the interior ministry, while about 735 educational establishments were affected on Friday, the education minister said.
2026-10-04 · assertive framing · What is fuelling school protests in France?
🔮 According to the motion, Zionism would be “treated as any other form of racism” and the party supports the establishment of a “single democratic Palestinian State in all of historic Palestine.”
🔮 According to the motion, Zionism would be “treated as any other form of racism”, and the party supports the establishment of a “single democratic Palestinian State in all of historic Palestine”.
2026-10-04 · assertive framing · UK's Green Party adopts 'Zionism is racism' policy
🔮 Muslimi also downplayed expectations over what the coming government offensive might accomplish.
🔮 A G20 leaders' summit will be held at a golf resort in Miami owned by U.S. President Donald Trump in mid-December.
🔮 The presidents of Egypt, Somalia, Sudan and Eritrea — all of whom have difficult relations with Ethiopia — were set to meet in the Egyptian city of Alamein on Sunday (October 4) to discuss the conflict.
🔮 Under Clayton, the new Super Intelligence Force — Trump’s preferred term for artificial intelligence — will ensure that the United States “continue to lead the world” in AI development, the president posted on his Truth Social platform.
Wire or desk byline, not an individual reporter.
Also by AFP
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 397 articles by AFP →

Topics

Anthropic Community Discourse Hacktron OpenAI

Subjects

OpenAI ORG · 5× Anthropic ORG · 4× Hacktron ORG · 4× Community ORG · 1× Discourse ORG · 1× Drew Pusateri PERSON · 1× Meta ORG · 1× Slack ORG · 1×

Narrative

A security research company said Friday it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks.
framing: assertive · carried by 1 article(s) · first seen 2026-09-18
2026-09-18 · Dawn
Researchers used Claude to breach OpenAI's internal systems · assertive framing

Claims (14 extracted, 0 hedged)

A security research company said Friday it managed to break into OpenAI’s internal systems using the latest software from Anthropic, exposing how quickly the technology can carry out sophisticated cyberattacks. asserted
technology → say → cyberattacks
The researchers from security firm Hacktron said they found a security flaw in OpenAI’s public help forum, run by the Discourse platform, that allowed them to take control of the site. asserted
them → say → site
“We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch,” Hacktron said in a blog post. asserted
Hacktron → report → post
“We appreciate their attention to detail and fast resolution of this issue,” the post added. asserted
post → appreciate → issue
OpenAI confirmed the flaw was fixed within about 14 hours of being notified and paid the researchers a $6,500 reward. asserted
flaw → confirm → reward
“We thank the researchers for contacting us and sharing their findings. asserted
We → thank → findings
We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” said Drew Pusateri, an OpenAI spokesperson. asserted
Pusateri → narrow → tokens
The Hacktron researchers said they initially used Anthropic’s Claude Opus 4.8 to identify and exploit the software flaw, but struggled to make it work consistently. asserted
it → say → flaw
After Anthropic released Claude Opus 5, the researchers said the newer model produced a working hack within about three hours. asserted
model → release → hours
The hackers did not use Claude Mythos, a more capable Anthropic model that is restricted to a small group of vetted cyber-defence organisations. asserted
that → use → organisations
Anthropic has described Mythos as having the strongest cybersecurity capabilities of any model it has built. asserted
it → describe → model
Hacktron said the underlying software flaw is not unique to OpenAI and is used across many companies’ products, including those made by Slack and Meta. asserted
flaw → say → Slack
The firm said it is continuing similar tests at other companies. asserted
it → say → companies
The case adds to growing concern among security experts that AI tools are making it faster and cheaper to carry out sophisticated cyberattacks that once required specialised teams and months of work. asserted
that → add → work
💬Give feedback
🕘History 🎫Support