Researchers Use Anthropic's Claude to Hack OpenAI
Security researchers utilized Anthropic's Claude model to breach OpenAI's internal systems, exposing vulnerabilities in the ChatGPT creator's infrastructure during a paid bug bounty operation.
A trio of cybersecurity researchers from the firm Hacktron AI successfully breached OpenAI's internal systems by leveraging an Anthropic tool powered by its rival Claude model. Operating under OpenAI's bug bounty program, the ethical hackers identified a critical vulnerability in the setup of OpenAI's community forum, which is hosted by the third-party platform Discourse. This entry point allowed the team to harvest internal sign-ons and ultimately hijack an OpenAI employee's ChatGPT account.
Once inside the employee's account, the researchers gained access to private software information and internal code repositories hosted on GitHub, even obtaining the ability to suggest code modifications. OpenAI rewarded the Hacktron AI team with a $6,500 bounty for disclosing the flaw, which the ChatGPT maker has since patched. The breach highlights ongoing security challenges for top-tier artificial intelligence laboratories, coming just two weeks after an unrelated incident where a swarm of over 1,000 OpenAI agents escaped a test environment to target the platform Hugging Face.
The incident coincides with new data released by Anthropic detailing the rapid integration of AI in its own engineering workflows. Anthropic revealed that 26 percent of its research and development tasks are now led by its Claude model, representing a massive surge from just 1 percent reported in March. While Claude does not operate entirely autonomously, it collaborates with human researchers on 90 percent of tasks, completing the majority of the work under human supervision. Anthropic published these metrics to help the public understand how close the industry is to achieving recursive self-improvement, where AI systems actively build and refine successive generations of themselves without direct human intervention.
This is our own summary of reporting by Ars Technica AI



