Security researchers used Anthropic’s Claude Opus 5 to carry out an OpenAI Claude breach that compromised an employee’s ChatGPT account and demonstrated access to the company’s internal GitHub environment.
The three-person team from cybersecurity startup Hacktron AI began the operation on July 23 while conducting responsible security research, which they later submitted through OpenAI’s bug-bounty programme. OpenAI awarded the researchers USD 6,500 after disclosure of the vulnerabilities.
The researchers exploited flaws involving an OpenAI community forum hosted on the third-party platform Discourse. The attack chain allowed them to obtain authentication access linked to an OpenAI employee and reach private internal resources.
According to accounts of the investigation, Claude Opus 5 helped the researchers develop working exploit code. Hacktron also used OpenAI’s own GPT-5.6 Sol during parts of the research.
The team demonstrated that it could reach private software repositories and submit a harmless proposed code change. Hacktron said it deliberately stopped short of examining or downloading OpenAI’s proprietary source code.
OpenAI subsequently fixed the vulnerabilities and tightened access controls, according to reports on the disclosure. The company’s vulnerability-disclosure policy encourages good-faith researchers to report security flaws through its bug-bounty programmes.
Read: OpenAI AI Safety Framework Tracks Six Concerning Cases
Hacktron said the exercise showed how advanced AI systems can compress sophisticated security research that previously demanded substantially more time and manpower. The incident involved human-directed ethical hacking, not Claude autonomously attacking OpenAI.