OpenAI, the maker of ChatGPT, was recently breached by a team of ethical hackers who used Anthropic’s Claude AI to crack into its internal systems.
The breach was carried out by Hacktron AI, a small US-based cybersecurity startup. The team consisted of three independent security researchers who participated in OpenAI’s bug bounty programme.
The programmed at rewarding ethical hackers for finding and reporting vulnerabilities before criminals can exploit them.
The researchers first tried using Anthropic’s Claude Opus 4.8, but it “struggled across several sessions to produce a working exploit.” But when they used Claude Opus 5, they succeeded.
They gained access to an OpenAI employee’s ChatGPT account, which gave them access to the company’s internal code on GitHub. They also reportedly used OpenAI’s own GPT-5.6 model for parts of the operation.
The team was also successful in accessing private software information and suggesting changes to OpenAI’s code. As per Hacktron, “the scope of what we could theoretically access was huge.” However, they emphasized that they didn’t download any code; they only accessed it to showcase the vulnerability.
The exercise indicates growing concerns about AI-powered cyberattacks. Hacktron noted that “work that once required a well-resourced team and months of effort can now be compressed into days.”