Security researchers exploit OpenAI vulnerabilities using Anthropic’s Claude AI
Independent cybersecurity researchers from startup Hacktron AI successfully breached OpenAI’s internal systems by exploiting vulnerabilities using Anthropic’s Claude AI platform, highlighting significant security concerns at the ChatGPT maker. The three-person team, consisting of Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, discovered and chained together two critical security flaws to gain unauthorized access to multiple OpenAI employee ChatGPT accounts, which subsequently allowed them entry into the company’s internal software environment and private GitHub repositories containing source code.
The attack was conducted as part of OpenAI’s legitimate bug-bounty program, with the researchers reporting their findings responsibly to the company. OpenAI responded promptly, fixing the identified vulnerabilities within approximately 14 hours of notification and awarding the Hacktron team a $6,500 bounty for their work. The initial breach occurred on July 25, 2026, when the researchers exploited a flaw in Discourse, the third-party software platform powering OpenAI’s community forum, specifically targeting a heap buffer overflow vulnerability in libheif, an open-source library used for processing HEIC and HEIF image files.
This incident comes at a time when leading AI companies face mounting scrutiny over safety and security practices. The breach demonstrates how quickly sophisticated AI models can be leveraged to discover and exploit software vulnerabilities, raising concerns about the potential for malicious actors to use similar techniques. OpenAI confirmed that all identified issues have been resolved, narrowing permissions on community sign-in tokens and revoking affected sessions. The Wall Street Journal first reported the incident, which underscores the growing importance of robust security measures in the rapidly evolving artificial intelligence industry.
