OpenAI âethically hackedâ with help of Anthropicâs Claude chatbot
Cybersecurity researchers have hacked into OpenAI with the help of Anthropicâs Claude chatbot, in the latest example of security issues at the company.
A team at a US-based startup compromised a number of OpenAI employeesâ ChatGPT accounts, starting a process that enabled them to access their targetâs software cache â and potentially more.
âThe scope of what we could theoretically access was huge,â said researchers at Hacktron AI.
Initially, the research team used Claude, which can generate code for hackers, to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform. They then made a harmless âpull requestâ â an attempt to change the code in a file â to OpenAIâs service on the GitHub software repository.
Hacktron reported the hack to OpenAI, having carried out the operation under an OpenAI programme that rewarded ethical hackers for testing its systems. The researchers stressed that they had access to, but did not download, the code from the GitHub repository.
Despite initial use of Claude, the researchers said they were largely using OpenAIâs own cutting edge GPT-5.6 Sol model to carry out the hack, which was first reported by the Wall Street Journal.
An OpenAI spokesperson said: âWe thank the researchers for contacting us and sharing their findingsâ, adding that the company had addressed the vulnerabilities that had been exploited.
Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack. This is a common refrain from cybersecurity experts when discussing the impact of AI.
âWork that once required a well-resourced team and months of effort can now be compressed into days,â said Hacktron, which received a $6,500 payment from OpenAI under the companyâs bug bounty programme.
The hack is the latest safety incident at OpenAI, which revealed in July that a âswarmâ of agents â the term for AI tools capable of carrying out tasks autonomously â powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test.
This week the San Francisco-based company revealed six more examples of âunexpected or concerningâ actions by its technology, and warned that the pace of development could not continue at âmaximum speed for much longerâ.
Anthropic made a fresh call at the weekend for a slowdown in AI development, which was supported by OpenAI, Google DeepMind and Elon Musk. Anthropic also repeated warnings that unrestrained AI development posed an existential threat, concerns that some experts are sceptical about.
Donald Trump has rejected calls for a slowdown, citing a need to stay ahead of Chinaâs AI industry and dismissing ânegative forces ⌠bringing up things that wonât happenâ.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.