Three researchers used Claude to break into OpenAI's internal systems, and OpenAI paid them for it.
Hacktron AI's team chained two separate weaknesses to reach OpenAI employee accounts and an internal code repository, all within 72 hours. One of the two flaws was a single sign-on vulnerability; the source material doesn't specify what the second one was. Neither flaw was an AI vulnerability itself - Claude reportedly helped the researchers work faster, not exploit anything unique to how AI systems behave. The team disclosed privately, OpenAI patched the SSO flaw in about 14 hours, and paid out a $6,500 bounty.
That speed is the real story here. A company as scrutinized as OpenAI closing a hole into employee accounts and source code in under a day suggests either a well-drilled incident response process or a flaw simple enough to patch fast - possibly both.
$6,500 buys a lot of goodwill for OpenAI, and a lot less than what that access would fetch on the open market.