Researchers Used Claude to Breach OpenAI's GitHub and Employee Accounts
A three-person white-hat team used Anthropic's Claude to compromise OpenAI employee accounts and an internal code repository in under 72 hours.
Five reports describe how security researchers used Anthropic's Claude to break into OpenAI's systems. The Verge, citing The Wall Street Journal, says a three-person team took less than 72 hours, using Claude Opus 4.8 and 5 to reach employee ChatGPT accounts and an internal GitHub repository. TechCrunch and Ars Technica similarly report access to employee accounts and sensitive code.
Tom's Hardware adds that the researchers left a harmless pull request as proof of access, and describes the group as white-hat hackers. The Register frames the result as another demonstration of agentic exploits, with Claude driving the attack chain. The researchers reported the flaws to OpenAI rather than using the access maliciously.
The main discrepancy is the group's name: The Verge calls it Hacktron, while Tom's Hardware writes Hackron AI. Otherwise, the accounts align on the method, the target, and the outcome.
Sources · 6
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
- Researchers used Claude to hack OpenAI employees' ChatGPT accounts
- Security researchers used Claude to help them hack into OpenAI
- Researchers used Anthropic’s Claude to hack into OpenAI
- Hackers breach OpenAI using Claude tools, gaining access to employee accounts and the company's internal codebase — attackers initiated a 'harmless' pull request as proof of the hack
- Researchers used Claude to hack OpenAI
More in Compute & Hardware
Accelerated Server Sales Show Accelerating Growth
A report from The Next Platform finds that sales of accelerated servers are growing at an increasing pace.
FCT Unveils Flex Circuit Leak Sensor for AI and HPC Liquid Cooling
Flexible Circuit Technologies has developed a custom leak-detection flex assembly aimed at protecting AI and high-performance computing systems from coolant failures.
Hardware Trojan Detection: Stable Patterns Found in Gate-Level Netlists
A new study from UW-Madison and Marist shows that RTL Trojans leave stable structural and signal-flow traces that can be localized at the gate level.
DKRZ Joins EU Project for AI Climate Models on HPC
Germany's climate computing centre is part of a new four-year Horizon Europe effort to make AI-based climate models usable on European supercomputing and AI infrastructure.