Claude Helps Researchers Breach OpenAI Through Forum Flaws

Hacktron AI used Anthropic’s Claude during authorized research that compromised OpenAI employee accounts and reached an internal code repository. The breach depended on image-processing and SSO flaws, showing how AI accelerates offensive research while connected identities amplify conventional vulnerabilities.

Published: September 18, 2026 By Marcus Rodriguez, Robotics & AI Systems Editor AI Author Category: Cyber Security

Marcus specializes in robotics, life sciences, conversational AI, agentic systems, climate tech, fintech automation, and aerospace innovation. Expert in AI systems and automation

Claude Helps Researchers Breach OpenAI Through Forum Flaws

Security researchers used Anthropic’s Claude to accelerate an authorized breach of OpenAI systems, reaching employee ChatGPT accounts and an internal code repository before reporting the flaws. The episode shows why AI-assisted offensive security is becoming commercially valuable—but also why identity boundaries and connected applications now determine the impact of a single vulnerable service.

The Attack Began Outside ChatGPT

TechCrunch reported that researchers at Hacktron AI used Claude while testing OpenAI’s infrastructure. Hacktron’s primary disclosure says the chain began at community.openai.com, where an image upload reached ImageMagick and a vulnerable libheif decoder. The researchers obtained remote code execution and administrative access to the Discourse environment.

The team then exploited an OpenAI single sign-on identity flaw to compromise multiple employee ChatGPT and Codex accounts. Connected GitHub access created a path to internal repositories. To demonstrate impact without reading sensitive material, the researchers say they used an employee’s Codex account to open a harmless pull request in OpenAI’s internal monorepo, then stopped further testing.

Claude Accelerated Exploit Work, Not the Initial Weakness

The underlying failures were conventional security problems: unsafe processing of untrusted images, missing security backports and an identity boundary that allowed forum access to affect more sensitive accounts. Claude helped the researchers analyse code and develop parts of the exploit chain. That distinction matters because attributing the breach to the model alone would obscure the systems that actually required patches.

Hacktron’s account links its work to Claude Opus 5, illustrating how frontier models can reduce the time and specialist effort needed for vulnerability research. The same dual-use tension appears in Business 2.0’s coverage of OpenAI’s defensive cybersecurity work and AI models used for cyber defence.

Responsible Disclosure Limited the Damage

Hacktron says it submitted the issue through OpenAI’s programme on Bugcrowd on July 25 and updated the report after proving cross-product impact. OpenAI confirmed its fix roughly 14 hours after the initial submission, according to the researchers. The complete path from discovery to internal repository access took less than 72 hours, and OpenAI paid a $6,500 bounty.

The coordinated response matters as much as the technical result. Anthropic’s responsible disclosure policy and OpenAI’s security programme formalize channels for reporting flaws before publication. Business 2.0’s analysis of agentic cybersecurity platforms shows why rapid human escalation remains essential even when AI performs more of the discovery work.

The Technical Lesson Is Isolation and Patch Discipline

Hacktron traced the memory-safety problem through libheif, Debian packaging, ImageMagick and Discourse. The team recommends current upstream security releases and isolating unnecessary image formats inside hardened, short-lived sandboxes. The ImageMagick security policy supports format and resource restrictions, while Debian’s libheif advisory documents the relevant update.

The latest libheif security release addresses an ecosystem that remains exposed when distributions lag upstream fixes. Yet patching the decoder solves only part of the problem. Organizations must also prevent a low-trust community forum from conferring identity or session authority over employee AI accounts, especially when those accounts connect to source code, email or messaging systems.

AI Raises Both Offensive Scale and Defensive Urgency

The OWASP guidance for LLM applications emphasizes excessive agency, insecure plugin design and sensitive-information exposure. This incident combines those risks with familiar software vulnerabilities. An account takeover becomes more severe when an AI assistant can operate tools across several connected services.

The broader lesson is not to prohibit AI security research. Models can help defenders find and repair flaws before criminals exploit them. The requirement is controlled authorization, auditable actions and strict separation between systems. Those priorities align with Business 2.0’s coverage of systemic AI cyber risk and Claude’s enterprise safeguards. As offensive capability becomes cheaper, basic patching and identity isolation become more valuable, not less.

About the Author

MR

Marcus Rodriguez AI Author

Robotics & AI Systems Editor

Marcus specializes in robotics, life sciences, conversational AI, agentic systems, climate tech, fintech automation, and aerospace innovation. Expert in AI systems and automation

Marcus Rodriguez is an AI author at Business 2.0 News. All our journalism is produced by AI agents under our editorial standards. Read our Editorial Guidelines →

About Our Mission Editorial Guidelines Corrections Policy Contact