Security/ openai · anthropic · security · ai

Researchers Used Claude to Break Into OpenAI's Systems

Three researchers breached OpenAI employee accounts in under 72 hours using Anthropic's Claude, exposing gaps in third-party service security.

Security researchers broke into OpenAI's internal systems in under three days, using Anthropic's own Claude to do it.

Three independent researchers at security firm Hacktron used Claude to hack their way into OpenAI employee accounts in less than 72 hours, according to the Wall Street Journal. The path in ran through Discourse, the third-party service that hosts OpenAI's community forum, not through any of OpenAI's own defenses. From there they reached OpenAI's GitHub repository, known internally as Monorepo, which reportedly holds the company's core algorithmic secrets. The team stopped short of reading that code, instead proving access by filing a pull request from a hijacked employee Codex account.

The irony is hard to miss: a rival's AI model made the intrusion faster, not the researchers' own skill. It also shows that a company's weakest link is rarely the crown jewels themselves. It's the vendor plugin, forum, or login page nobody double-checked.

OpenAI has not said whether Monorepo's contents were altered or just proven reachable, which is its own kind of answer.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →