Cybersecurity researchers from Hacktron discovered vulnerabilities in OpenAI's systems earlier this year, allowing them to access employees’ ChatGPT accounts by exploiting a flaw in Discourse software and an employee validation process. The breach occurred within 72 hours in late July. OpenAI confirmed the incident and noted that they have since patched the vulnerabilities; they also paid Hacktron $6,500 under their bug bounty program. This event highlights growing concerns about AI security and safety amid increasing competition and fears of economic espionage involving advanced persistent threats.
Written locally by qwen2.5:14b on 2026-09-19,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.
Written for “AI Breach Risks” on 2026-10-05,
grounded in this article and the 7 other(s) covering the same event.
A small group of cybersecurity researchers said Sunday that they broke into OpenAI earlier this year, an announcement that has added a new element of alarm around AI security and safety.
asserted
that → say → security
The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts.
uncertain
they → call → accounts
As is customary for researchers — sometimes called “white-hat hackers” — they caused no harm to the company’s systems.
asserted
they → call → systems
Hacktron conducted the entire operation within 72 hours in late July, soon after some of OpenAI’s agents broke containment and hacked the AI platform Hugging Face.
asserted
some → conduct → platform
An OpenAI spokesperson confirmed Hacktron’s report and said the vulnerabilities have since been patched.
asserted
vulnerabilities → confirm → report
“We thank the researchers for contacting us and sharing their findings,” the spokesperson said.
asserted
spokesperson → thank → findings
The news comes as concerns about AI safety have exploded into public view in recent weeks.
asserted
concerns → come → weeks
Safety researchers have resigned from major companies and issued stern warnings that the advanced technology could pose a risk to the human race, and politicians from across the political spectrum have called for action.
uncertain
politicians → resign → action
While most of those concerns have centered on the capabilities of advanced AI models, the security of the companies themselves is also a significant issue.
asserted
security → center → companies
AI development is extremely competitive, and concerns of theft — primarily through a process known as distillation — abound.
asserted
concerns → know → distillation
Like many companies, OpenAI maintains a “bug bounty” program, which offers to pay cybersecurity researchers who find novel ways to hack it instead of selling them to malicious hackers who would do the company harm.
asserted
who → maintain → harm
Hacktron’s researchers wrote in their blog post that OpenAI paid them $6,500 for the discovery.
asserted
OpenAI → write → discovery
There is no evidence that any other hackers exploited the same vulnerabilities that Hacktron did.
asserted
Hacktron → be → vulnerabilities
But American countries have for years accused Chinese intelligence of economic espionage, saying China’s elite government hackers routinely share stolen trade secrets with Chinese companies.
asserted
hackers → accuse → companies
China broadly rejects the accusations.
asserted
China → reject → accusations
More recently, the U.S. formally accused the Chinese AI industry of systematically distilling against American AI companies.
asserted
U.S. → accuse → companies
Greg Linares, a cybersecurity researcher at Persona, a company that helps authenticate users, said that Hacktron’s finding would have given China or other countries’ elite hackers the ability to break into OpenAI systems.
asserted
finding → help → systems
“What they chained together was not untypical from what very high-level real-world attackers, such as APTs or nation-state-backed hackers, would use to compromise targets,” Linares told NBC News, using the abbreviation for “advanced persistent threats,” meaning hacker groups that operate in perpetuity and are usually state-backed or state-adjacent.
asserted
that → chain → perpetuity
“The hack conducted demonstrates the need for constant vigilance in these environments and when there’s so many moving parts and the pressure to constantly develop and be delivering; patches get neglected, configurations get missed and cracks in layers of security get exposed,” he said.
asserted
he → conduct → security