Researchers used Claude to reach OpenAI employee accounts
Claude
An AI system made by Anthropic that helps with language and tasks.
bug bounty program
A program that rewards people who report security problems.
internal GitHub repository
A private place where a company stores software code.
What happened
Three independent security researchers at Hacktron, a security research team, used Claude to examine OpenAI’s systems. Anthropic is the company behind Claude. OpenAI is the company behind ChatGPT. Reports from TechCrunch, The Verge, and Ars Technica say the team found several weaknesses that could be connected together. They used that path to take over multiple OpenAI employee accounts. From there, they reached an internal GitHub repository. The reported timeline was less than 72 hours. The researchers worked through OpenAI’s bug bounty program. They reported the problem, and OpenAI awarded them $6,500. OpenAI also said it fixed the issues. TechCrunch’s report, The Verge’s report, and Ars Technica’s report describe the incident.
The background
A bug bounty program gives outside researchers a formal way to report security problems. It can turn a risky discovery into a controlled test. In this case, the researchers did not keep the finding secret. They informed OpenAI and the related software provider.
Claude was important because it helped with the investigation. TechCrunch reported that an earlier Claude version struggled with the task. The researchers said a newer version succeeded after its release. That detail suggests that model capability can change quickly. It does not prove that Claude acted alone. The public reports describe a human team directing and checking the work.
Why it matters
The news is not simply that one company had a bug. The larger issue is that AI can help with difficult security work. A capable model can search, reason, and repeat tasks quickly. That may reduce the time and expertise needed to find a weak point. The same ability can help defenders review software and test protections. It can also make mistakes or move faster than a team expects.
An employee account can matter because it may connect to other company systems. A problem in one service can therefore become a path toward more sensitive areas. This is why account permissions, software updates, and independent testing matter. The incident does not show that secrets were stolen. It shows that the boundary around important systems was reachable.
What is confirmed
The reports agree on the central sequence: three researchers used Claude, reached OpenAI employee accounts, demonstrated access to an internal code repository, disclosed the problem, and received a reward. OpenAI said it fixed the issues. Discourse, the outside forum software involved in the reported path, also issued a fix. The stories describe a bug-bounty investigation, not a random break-in against customers.
What remains unknown
The public reports do not establish exactly which files were viewed or copied. They do not give a complete account of every account involved. They also do not show whether the same kind of weakness affected other organizations. It is unclear how much of the work Claude performed and how much came from the researchers. Those details matter when people estimate the real risk.
What to watch next
The next questions are practical. Will AI companies tighten employee-account permissions? Will they test third-party software more often? Will bug-bounty programs expand to cover AI-assisted research? And will independent evaluators check whether fixes work after the headlines fade?
The clearest lesson is balanced. Claude was used to help find a weakness, and the same discovery process helped the company repair it. AI can strengthen security, but it can also amplify mistakes and attacks. The safety challenge is making sure people remain in control of both sides.
Researchers used Claude to find a path into OpenAI accounts
📰 Full story: Researchers used Claude to reach OpenAI employee accounts
An AI helped researchers find a security problem inside OpenAI. The company says it fixed the problem.
bug bounty program
A program that pays people for reporting safety problems.
internal code store
A private place where a company keeps its software code.
💡 The gist
- Three researchers used Claude to find a path into OpenAI employee accounts.
- The path reached an internal place where OpenAI stores code.
- OpenAI fixed the problems and paid a $6,500 reward.
Anthropic is the company behind Claude. OpenAI is the company behind ChatGPT. Hacktron is a security research team. Three people from Hacktron checked OpenAI’s systems with Claude. Claude helped them search and think through the problem.
The team found more than one weakness. They connected those weaknesses. This let them take over some employee accounts. One account could reach an internal code store. The reports say the whole test took less than 72 hours.
This was part of OpenAI’s bug bounty program. A bug bounty pays researchers who report safety problems. It gives companies a chance to fix problems before criminals use them. The team told OpenAI what they found. OpenAI said it fixed the problems. A related software maker also released a fix. The team received $6,500.
The reports also mention model improvement. An earlier Claude version struggled. A newer version solved the same task, researchers said. That does not mean every user can repeat the result. It does show why security teams must test new models.
The important point is not that Claude has a magic key. People chose the target and checked the results. Claude was a tool in their work. Still, a fast tool can change who can do difficult security research. Someone with less experience may be able to search more possibilities. That can help defenders, too. They can use AI to find weak points before attackers do.
An internal code store is not a public webpage. Reaching it does not prove that every file was read. The public reports do not say that customer data was stolen. They also do not say which files were opened or copied. We do not know whether other companies have the same problem. We should watch how AI companies protect employee accounts, update outside software, and test their fixes.
This story has two sides. AI can help find a dangerous door. It can also help people close that door. Safety depends on doing both jobs quickly.
Claude helped people find a weak place in a company
📰 Full story: Researchers used Claude to reach OpenAI employee accounts
Three people used Claude to find a weak way into OpenAI’s computer systems.
Claude
An AI that reads words and helps with tasks.
Anthropic is the company that makes Claude. Claude is an AI that reads words and helps with tasks. Three people at Hacktron used it to check OpenAI, the company that makes ChatGPT.
They found a weak way into some worker accounts. They could also reach a private place where OpenAI keeps code. They told OpenAI about the problem. OpenAI fixed it and gave them a reward.
Think of a house with a loose door. The visitors did not keep the loose door secret. They told the owner, so it could be fixed.
We do not know what pages they saw. We do not know if anything important was copied. The big lesson is simple. A tool that helps can also help find unsafe places. People must use it carefully.