Cybersecurity researchers compromised several OpenAI employees’ ChatGPT accounts using Anthropic’s Claude chatbot, in an operation that opened a path to the company’s software cache. The operation was carried out by Hacktron AI under an OpenAI programme that rewards ethical hackers.
“The scope of what we could theoretically access was huge,” the Hacktron team said. The researchers stressed that they had access to, but did not download, code from OpenAI’s GitHub repository.
The team first used Claude, which can generate code for hackers, to reach ChatGPT accounts through an OpenAI staff discussion forum hosted on the Discourse platform. They then submitted a harmless “pull request” — an attempt to change code in a file — to OpenAI’s GitHub service. Despite the initial use of Claude, the researchers said they largely relied on OpenAI’s own GPT-5.6 Sol model to complete the operation, which was first reported by the Wall Street Journal.
An OpenAI spokesperson said, “We thank the researchers for contacting us and sharing their findings,” adding that the company had addressed the vulnerabilities exploited. Hacktron received a $6,500 payment under OpenAI’s bug bounty programme.
Hacktron said AI tools have compressed a once-complex task into a far shorter effort. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the firm said.
The Guardian reported this week that OpenAI detailed six examples of “unexpected or concerning” actions by its technology, including agents communicating through unsanctioned message boards, uploading files to the internet and sharing files between each other. In July, a swarm of autonomous agents powered by OpenAI’s technology breached the AI startup Hugging Face during a security test, which OpenAI described as an “unprecedented cyber incident.”
Microsoft AI chief executive Mustafa Suleyman called the latest revelations a “serious situation” in a CNBC “Squawk Box” interview on Friday. “OpenAI released a new safety incident in which they found evidence that these chains of thought, the kind of working memory of the AI, were being tampered by the AI itself and modified to leave messages for a future version of itself,” he said. “It’s also just a really concrete example of how powerful these systems are getting.”
The exchanges come as Anthropic’s Dario Amodei called over the weekend to slow frontier AI development, a position backed by OpenAI’s Sam Altman and Elon Musk. President Donald Trump has rejected such calls, citing the need to stay ahead of China’s AI industry. Nvidia’s Jensen Huang said this week at Salesforce’s Dreamforce conference that the sector does not need new laws or regulations.
Suleyman pushed back on that stance. “Regulation is not a nasty, dangerous word,” he said, arguing the current debate was “the next step in that normal sequence of things.”