Story
September 18, 2026

Claude Helped Hack OpenAI—And Exposed a Bigger Security Race

Hacktron frames the breach as responsible research that reveals a rapidly changing cyber landscape, while OpenAI says it contained the exposure by tightening permissions and revoking affected access. The common warning is stark: powerful AI tools are making sophisticated intrusion work more accessible.

In July, the small San Francisco AI-security startup Hacktron began probing frontier AI companies for weaknesses that could be exploited by AI agents. Its target was OpenAI—and its most consequential tool came from OpenAI rival Anthropic.

On July 25, Hacktron found an entry point in OpenAI’s community forum, which ran on Discourse. A specially crafted HEIF or HEIC image could exploit a bug in the libheif image-processing chain and seize control of the forum server. The vulnerability had reportedly been fixed upstream months earlier, but had not been formally catalogued with a CVE, leaving the affected software in use.

Hacktron said Claude initially could not produce a working exploit. Then Anthropic released Opus 5. “Opus 4.8 struggled across several sessions to produce a working exploit,” the researchers wrote. “Within hours of Opus 5’s release, we gave it the same problem and it succeeded.”

The team chained that foothold to a second flaw, allowing it to take over ChatGPT and Codex accounts—including an OpenAI employee’s. Hacktron said it stopped before accessing internal code, though it demonstrated that the employee’s Codex could be prompted to propose changes to OpenAI’s internal repository.

Hacktron alerted OpenAI and Discourse rather than pushing further. Discourse issued a fix on July 27; OpenAI later awarded the researchers $6,500. An OpenAI spokesperson said the company had “narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”

For Hacktron, the incident is evidence that AI safety and cybersecurity are colliding. Founder Mohan Pedhapati argued that AI is reducing the scarce expertise needed to build exploits, compressing work that once took months into days. For defenders, that is less a futuristic warning than a present-tense challenge: even a highly resourced AI company can be tested by a tiny team with a $200-a-month model subscription.