Researchers Use Claude to Breach OpenAI
Security researchers used Claude during an authorised OpenAI bug-bounty investigation to chain vulnerabilities and reach internal systems.

A security team used a frontier AI model to help chain vulnerabilities during an authorised investigation of OpenAI's systems, showing how quickly AI-assisted offensive research is improving.
What happened
A three-person team at Hacktron AI used Claude during an OpenAI bug-bounty investigation to combine several weaknesses, gain access to multiple employee ChatGPT accounts and eventually reach an internal GitHub environment.
OpenAI fixed the vulnerabilities and paid the researchers a $6,500 bounty.
The researchers said an earlier model struggled to build a working exploit while a newer Claude model completed important parts of the task within hours.
Why it matters
AI is lowering the time and expertise required for complex security research. That can benefit defenders because smaller teams can test systems more thoroughly, but the same capabilities can also be used by malicious actors.
The important shift is not that a model can write exploit code in isolation. It is that models are becoming better at combining information across several weaknesses and navigating multi-step attack paths.
The bigger picture
Cybersecurity is entering an arms race between AI-assisted defenders and AI-assisted attackers. As models become more autonomous, organisations will need stronger identity controls, sandboxing, monitoring and faster patching rather than relying only on restrictions around what models are willing to say.
