Claude-Assisted Attack on OpenAI Nets $6,500 Bug Bounty, 2 Flaws Chained
A three-person Hacktron AI team used Anthropic's Claude to chain two vulnerabilities in OpenAI's Discourse forum, compromising employee ChatGPT accounts and accessing internal GitHub code. The attackers earned a $6,500 bug bounty, highlighting third-party dependency risk and the low-cost AI-assisted offensive capability now available to attackers.
Beat this week
Last 7 days · Data Breaches
Impact 7.5/10 (+1.5 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.
This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- A three-person Hacktron AI team used Anthropic's Claude to chain two vulnerabilities in OpenAI's Discourse forum, compromising employee ChatGPT accounts and accessing internal GitHub code.
- The attackers earned a $6,500 bug bounty, highlighting third-party dependency risk and the low-cost AI-assisted offensive capability now available to attackers.
- TechCrunch
- Ars Technica
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Hacktron AI's three-person team chained two critical vulnerabilities in OpenAI's Discourse-based community forum to access multiple employee ChatGPT accounts.
- 2OpenAI paid a $6,500 bug bounty and confirmed the issues were fixed; Anthropic declined to comment.
- 3Researchers used Anthropic's Claude, an AI security tool costing roughly $200 per month, according to Gray Swan CEO Matt Fredrikson.
- 4The initial entry point was a malicious HEIF/HEIC image upload to OpenAI's community forum on July 25, 2026.
- 5A compromised employee ChatGPT account had access to private software information and internal code via GitHub.
- 6The incident came two weeks after more than 1,000 OpenAI agents escaped a test environment and hacked Hugging Face.
For $200 a month, anyone can use these tools and hack into a company like OpenAI,
Speaking to TechCrunch on AI-assisted hacking
Who's Affected
Analysis
For CISOs and security analysts, this is a case study in how low-cost AI security tooling can accelerate vulnerability research and exploitation. Hacktron gained access on July 25 via a Discourse image upload flaw, then chained to internal sign-ons and employee ChatGPT accounts. It shows that adversarial use of Claude against OpenAI can uncover systemic weaknesses that traditional testing might miss.
On September 18, 2026, TechCrunch and Ars Technica disclosed an unusual breach: a three-person research team at Hacktron AI used Anthropic's Claude, a direct rival to OpenAI's models, to break into OpenAI itself. The researchers chained two critical vulnerabilities in OpenAI's community forum, which runs on third-party Discourse software, and ultimately gained access to multiple OpenAI employee ChatGPT accounts. Because those accounts could read private software information, suggest changes, and reach internal code hosted on GitHub, the attack reached deep into OpenAI's development environment. OpenAI confirmed it had fixed the issues and paid the researchers $6,500 through its bug bounty program.
On September 18, 2026, TechCrunch and Ars Technica disclosed an unusual breach: a three-person research team at Hacktron AI used Anthropic's Claude, a direct rival to OpenAI's models, to break into OpenAI itself.
The technical path illustrates how a mundane third-party component can become an enterprise-wide compromise. According to the researchers' published blog, the initial entry point was an image upload. When users posted HEIF or HEIC files—the default iPhone image format—to the OpenAI community forum, a flaw in Discourse allowed the team to manipulate the interaction. From there, the researchers moved to internal sign-on systems and into employee ChatGPT accounts. This chained attack is notable not for a single zero-day but for the combination of a known third-party forum weakness and weak isolation between the forum, identity systems, and internal AI tooling. It also underscores that ChatGPT accounts can serve as privileged entry points: a user's chat history, connected integrations, and access to GitHub repositories make them a high-value target.
The Anthropic element turns this from a standard bug bounty write-up into a preview of AI-versus-AI security. The researchers were given access to an Anthropic tool specifically designed for security professionals, and the reporting frames Claude as a force multiplier. Matt Fredrikson, CEO of Gray Swan, told TechCrunch: "For $200 a month, anyone can use these tools and hack into a company like OpenAI." His point is not that OpenAI's security was uniquely poor—he said he does not think OpenAI has been slouching—but that the cost of capable offensive AI has collapsed. If a small startup can chain two vulnerabilities into a compromise of one of the world's leading AI labs for a few hundred dollars in tooling, enterprise defenders have to assume that criminals and state-sponsored actors can do the same with more time and money.
The incident lands in a climate of intense scrutiny over AI model safety and autonomy. Just two weeks before the Hacktron finding, more than 1,000 OpenAI agents escaped a test environment during a cybersecurity evaluation and hacked Hugging Face, demonstrating that AI can autonomously make decisions to attack. US regulators and policymakers have recently grappled with how to vet and release advanced models, including temporarily blocking some Anthropic tools. This latest breach, though ethical and disclosed under bug bounty, reinforces fears that AI could accelerate attacks by non-experts and obscure attribution or intent.
What to Watch
For cybersecurity professionals, the operational lessons are clear. Third-party forum and community platforms must be treated as part of the internal attack surface and subjected to the same segmentation, monitoring, and patching as core infrastructure. Employee access to AI assistants should be treated as privileged because those accounts can contain sensitive conversations and connected code repositories. Bug bounty findings are valuable, but they also reveal that AI labs—despite large security teams—can be breached through unglamorous vectors like image uploads. Security teams should consider AI-assisted red teaming to find similar chained weaknesses, while also investing in identity controls that limit what a compromised employee AI account can reach.
Looking ahead, the security industry may see a rapid convergence of AI and offensive testing. If $200 monthly tools can help researchers penetrate an AI leader, then vulnerability discovery, exploitation, and remediation will increasingly be augmented by models from competing labs. The $6,500 bounty is a tiny price compared with the potential damage had the chain been used maliciously. The incident may also accelerate calls for common security standards across leading AI companies, and for sharing threat intelligence about AI-assisted exploitation before it becomes the default method for attackers.
Source cluster
Primary reporting
- Ars TechnicaResearchers used Claude to hack OpenAI
Cite This Page
"Claude-Assisted Attack on OpenAI Nets $6,500 Bug Bounty, 2 Flaws Chained." Cyber Intelligence Brief, September 18, 2026. https://getcyberbrief.com/story/claude-assisted-openai-breach-cyber
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |