Hackers Used Claude to Break Into an OpenAI ChatGPT Account and Access GitHub

Hackers Used Claude to Break Into an OpenAI ChatGPT Account and Access GitHub

Security researchers used Anthropic’s Claude to help exploit vulnerabilities that ultimately gave them access to an OpenAI employee’s ChatGPT account and a route into the company’s internal GitHub environment, exposing how AI coding tools can accelerate sophisticated cyberattacks even when used as part of authorized security testing.

The researchers, from security startup Hacktron AI, carried out the work through OpenAI’s bug bounty program and were ultimately paid $6,500. OpenAI said it fixed the issues after they were reported.

The attack began with OpenAI’s community forum, which is hosted on the third-party Discourse platform. Hacktron found that certain HEIC and HEIF image uploads could reach a vulnerable version of the libheif image-processing library, allowing the researchers to develop an exploit capable of remote code execution.

That foothold alone did not provide access to OpenAI’s internal systems. Hacktron said it then identified a separate weakness in OpenAI’s single sign-on configuration that allowed control of the forum environment to be turned into access to accounts that had authenticated through the service, including an OpenAI employee’s ChatGPT account.

The employee account was connected to OpenAI’s developer infrastructure through Codex and GitHub. Rather than examining sensitive source code, Hacktron said the researchers used Codex to make a harmless change and prepare a pull request inside OpenAI’s internal monorepo, demonstrating how far the compromised credentials could reach.

“We thank the researchers for contacting us and sharing their findings,” OpenAI said. The company also said it narrowed permissions on Community sign-in tokens and revoked affected tokens and sessions.

Discourse separately confirmed the underlying image-processing vulnerability and patched affected versions while adding additional sandboxing around image handling.

Anthropic’s role came during development of the exploit itself. Hacktron said the team initially worked with Claude Opus 4.8 but had difficulty making the attack reliable. After moving to Claude Opus 5, the researchers said the model helped produce a working ARM64 exploit within hours and assisted in adapting it to the environment used by Discourse.

Hacktron said the full process from discovery to demonstrating access to OpenAI’s repository environment took less than 72 hours.

The incident shows how AI coding agents can reduce some of the specialized work traditionally required to turn software bugs into usable exploits. At the same time, it highlights the security consequences of giving AI accounts access to other corporate systems.

Hacktron said affected accounts could potentially connect to services such as GitHub, Slack, Outlook, Gmail and Google Drive. In the OpenAI case, the compromised employee account’s connection to GitHub meant the breach extended beyond a standalone chatbot account and into developer infrastructure.

That interconnected access increases the consequences of an identity compromise. An AI account that can reach code repositories, communications systems and document stores can effectively inherit the permissions granted across those services.

The disclosure also arrives as AI labs increasingly use their own models for research and development. Anthropic separately said that 26% of its research and development work was now “led by” Claude, up from 1% in March. The company defined that category as work in which AI completed most of a task based on human instructions and supervision.

Anthropic said its systems still did not operate fully autonomously in the research it examined. It said humans and AI collaborated on 90% of tasks, with the models carrying out substantial portions of the work.

The company said it released the figures to help the public “understand how close the world is to reaching recursive self-improvement,” referring to the point at which AI systems can contribute increasingly to the development of later systems.

For security teams, the OpenAI breach presents a more immediate issue: the same AI agents being connected to increasingly sensitive business systems are also becoming more capable at assisting with technically demanding exploit development. In this case, researchers working under an authorized bounty program were able to combine a third-party software flaw, an identity weakness and connected developer tools into a path that reached OpenAI’s internal environment.

This analysis is based on reporting from Financial Times.

Image courtesy of Bitcoin News.

This article was generated with AI assistance and reviewed for accuracy and quality.

Updated Sep 18, 2026

About this article: This article was generated with AI assistance and reviewed by our editorial team to ensure it follows our editorial standards for accuracy and independence. We maintain strict fact-checking protocols and cite all sources.

Word count: 684Reading time: 0 minutes

📧 Stay Updated

Get the latest AI news delivered to your inbox every morning.

AI News Daily

Breaking Intelligence • Since 2023

Join hundreds of thousands of AI professionals who start their day with our curated newsletter. Get breaking news, expert analysis, and exclusive insights.

Stay Ahead of AI

Get the latest AI breakthroughs, tools, and insights delivered to your inbox every week.

Free forever Unsubscribe anytime No spam guarantee

Go Premium

Unlock unlimited AI tools and an ad-free reading experience designed for AI professionals.

• Ad-free experience• Premium AI tools
Start Free Trial

14-day free trial • Cancel anytime
Plus $9/mo • Pro $90/yr (2 months free)

Follow Our Community

ChatAI

Breaking Intelligence

Your daily briefing on what matters in AI. Trusted by developers, researchers, executives, and AI enthusiasts worldwide.

© 2026 ChatAI. All rights reserved.