AI security experts say they used Claude to hack ChatGPT

Read the original at CBS News ↗
CBS News · collected 2026-09-18 · by Megan Cerullo

Quick Summary

Hacktron AI security researchers used Anthropic's Claude platform to exploit vulnerabilities in OpenAI’s ChatGPT, gaining access to an employee’s account within 72 hours and retrieving sensitive information including source code storage details. The breach was reported to OpenAI, which addressed the issue swiftly and offered a $6,500 bounty for disclosing the vulnerability. This incident highlights growing concerns over AI security as leading developers advocate for slower development due to potential risks.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
16
claim-shaped sentences
Uncertain
12%
2 of 16 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
65.6
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 12% of its claims. Each row says how that neighbour differs.
CBS News · 0.91 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 3 📰 publisher trust 66
“Both articles describe the same incident where Hacktron AI used Anthropic's Claude to hack OpenAI's ChatGPT, mentioning retrieval of data and access to a discussion forum.”
The Straits Times · 0.87 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 15 📰 publisher trust 59
“Both articles describe researchers using Claude to breach OpenAI's internal systems and access their forums on the same date, September 18, 2026.”
The Guardian · 0.87 cosine similarity
⚖️ Leans right 🔴 13% hedged 2 of 15 📰 publisher trust 68
“Both articles describe a single incident where Hacktron AI used Anthropic's Claude to hack into OpenAI’s ChatGPT accounts, accessing employee data and forum discussions on the same day.”
BBC News
⚖️ Leans left 🔴 16% hedged 3 of 19 📰 publisher trust 78
“Article A discusses six safety issues revealed by OpenAI, while Article B reports on a hack of ChatGPT using Claude, which are different incidents.”
New York Post
⚖️ leaning not scored 🔴 0% hedged 0 of 11 📰 publisher trust 64
“Article A discusses OpenAI's new framework for tracking AI misalignment, while Article B reports on a security breach where researchers used Claude to hack into ChatGPT.”
Global News
⚖️ leaning not scored 🔴 7% hedged 2 of 27 📰 publisher trust 64
“Article A discusses six reported incidents of AI misalignment by various models, while Article B reports a specific hacking incident involving Claude and ChatGPT conducted by security researchers.”
Semafor
⚖️ Centre 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe the same incident where researchers used Anthropic’s Claude technology to hack into ChatGPT, with details about accessing an employee's account and retrieving source code information.”
Washington Examiner
⚖️ Leans left 🔴 21% hedged 9 of 42 📰 publisher trust 72
“Article A discusses multiple incidents where AI agents hacked during security evaluations, while Article B specifically mentions a hack of ChatGPT by Hacktron AI using Claude.”
Times of India
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 59
“Both articles describe the same security breach conducted by Hacktron AI researchers using Claude to hack into OpenAI's systems, including employee ChatGPT accounts and accessing internal code repository.”
NBC News
⚖️ leaning not scored 🔴 11% hedged 2 of 19 📰 publisher trust 95
“Both articles describe the same security breach by Hacktron AI using Claude to gain access to OpenAI employee's ChatGPT accounts on the same date.”

Publisher

CBS News · 1977 article(s) · 6 correction(s) detected
Running correction rate · 6 correction(s)
2026-10-03
Tennessee prison system head to resign after failed Christa Pike execution
2026-10-02
Christa Pike unconscious, on ventilator after botched execution: Lawyers
2026-10-01
Rick Ross arrested on domestic violence charges in Miami Beach
2026-09-17
After nitrogen execution blocked, Alabama inmate to die by lethal injection
2026-09-14
The AI bubble is leaking air, some economists say. Should investors worry?
2026-08-24
Sean Grayson, convicted in killing of Sonya Massey, dies in prison, attorney says

Who wrote this

Megan Cerullo
18 article(s) here · 1 carrying a prediction
🔮 American Airlines customers will soon be able to mix cash and airline miles to pay for flights.
🔮 Amazon said the money will go toward education, job training, energy affordability, and water and energy preservation, and also fund other local priorities.
🔮 When will Amazon customers get their money?
🔮 Americans traveling for the holidays this year could face sticker shock as high jet fuel costs stemming from the drive up domestic airfares, according to a new forecast.
🔮 The unaccredited program, called the Horowitz Andreessen Academy, will focus its curriculum on teaching people how to build products and services from the ground up using AI.
🔮 Central to the dire warnings about artificial intelligence's potential is the risk that a "swarm" of AI agents could collaborate in nefarious ways, like hordes of digital extras from The Matrix.
🔮 The breach comes as AI's capabilities and vulnerabilities have been thrust into the spotlight, with leading tech developers calling for a slowdown in building AI platforms due to concerns that they could harm people.
🔮 For example, healthcare providers may send a bill with erroneous charges, and the consumer should dispute them if they believe the charges were a mistake.
🔮 Artificial intelligence could one day supercharge human cognition, leading to significant advances in science, technology and other fields.
🔮 "It could potentially go buy a car, but I wouldn't say, 'Here's my credit card.'
Also by Megan Cerullo
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 18 articles by Megan Cerullo →

Topics

Anthropic ChatGPT Claude Hacktron AI OpenAI

Subjects

OpenAI ORG · 9× Hacktron AI ORG · 4× Anthropic ORG · 3× CBS News ORG · 1× Community ORG · 1× Dario Amodei PERSON · 1× Discourse ORG · 1× Hacktron ORG · 1× Journal ORG · 1× The Wall Street Journal ORG · 1×

Narrative

Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool, adding to mounting concerns about the vulnerability of leading large language models to cyberattacks.
framing: assertive · carried by 1 article(s) · first seen 2026-09-18
🔮 The breach comes as AI's capabilities and vulnerabilities have been thrust into the spotlight, with leading tech developers calling for a slowdown in building AI platforms due to concerns that they could harm people.
2026-09-18 · CBS News
AI security experts say they used Claude to hack ChatGPT · assertive framing

Claims (16 extracted, 2 hedged)

Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool, adding to mounting concerns about the vulnerability of leading large language models to cyberattacks. asserted
researchers → use → cyberattacks
Researchers from Hacktron AI, an independent AI security platform that tests software code, disclosed the breach in a blog post on Sunday. asserted
that → test → Sunday
They said they used Claude to gain access to an OpenAI employee's ChatGPT account, enabling Hacktron AI to retrieve key data on where the source code was stored and managed. asserted
code → say → data
They also accessed an OpenAI discussion forum. asserted
They → access → forum
"The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours," Hacktron AI said in the post. asserted
AI → take → post
The Hacktron AI team reported the intrusion to OpenAI, which responded promptly and paid researchers a $6,500 bounty, Hacktron AI said in its blog post. asserted
AI → report → post
"We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate the patch. asserted
We → report → patch
We appreciate their attention to detail and fast resolution of this issue," the researchers wrote. asserted
researchers → appreciate → issue
The incident was first reported by The Wall Street Journal. asserted
incident → report → Journal
"We thank the researchers for contacting us and sharing their findings. asserted
We → thank → findings
We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions," OpenAI said, according to the Journal. uncertain
OpenAI → narrow → Journal
Anthropic and OpenAI did not immediately respond to requests for comment. asserted
Anthropic → respond → comment
The breach comes as AI's capabilities and vulnerabilities have been thrust into the spotlight, with leading tech developers calling for a slowdown in building AI platforms due to concerns that they could harm people. uncertain
they → come → people
In July, OpenAI revealed that its bots had collaborated to , Hugging Face, after escaping a testing environment. asserted
bots → reveal → environment
In a recent interview with CBS News, Anthropic CEO Dario Amodei said "slow the pace" of AI development. around AI, citing the Hugging Face hack as a warning sign. asserted
Amodei → say → sign
In a Sept. 12 essay, he also wrote that the entire tech industry must work together to asserted
industry → write → essay
💬Give feedback
🕘History 🎫Support