TLDR
- Security startup Hacktron AI used Anthropic’s Claude AI to breach an OpenAI employee’s ChatGPT and Codex accounts
- Researchers gained access to OpenAI’s internal GitHub code, Outlook, Slack, and other connected services
- The hack took under 72 hours and cost less than $3,000 in AI tokens
- OpenAI fixed the vulnerabilities within 14 hours and paid a $6,500 bug bounty
- Ethereum co-founder Vitalik Buterin said AI hacking won’t break crypto, but urged security teams to move fast
Researchers at cybersecurity startup Hacktron AI used Anthropic’s Claude AI models to break into an OpenAI employee’s account and access the company’s internal code. The breach was done as part of OpenAI’s official bug bounty program.
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵 pic.twitter.com/gVsmQZwSc8
— s1r1us (@S1r1u5_) September 18, 2026
The team used two bugs found in ChatGPT and Codex accounts to get inside. From there, they reached connected services including GitHub, Outlook, and Slack.
“We proved it with a PR in OpenAI’s internal codebase. It took us less than 72 hours,” said Hacktron founder s1r1us.
How Claude Powered the Hack
The team first tried using Anthropic’s Claude Opus 4.8, but it struggled to produce a working exploit. When Anthropic released Opus 5, they tried again and succeeded.
The researchers ran the model in an autonomous loop against a test environment before applying the script to OpenAI’s live forum. The whole operation required only a few hours of human time.
Claude was given to the researchers through a special version made available to qualified cybersecurity practitioners, according to reports.
The breach was part of a wider research project called “HEIF Heist.” It explored a vulnerability in how software processes HEIC and HEIF image files. The same exploit found weaknesses in Slack, Zoom, and Meta products. The entire project cost less than $3,000 in AI tokens and took two months with three researchers.
OpenAI confirmed the vulnerabilities and fixed them within 14 hours. The company paid Hacktron a $6,500 bounty and thanked the team for their responsible disclosure.
Broader Warnings From the AI Industry
The hack came shortly after a separate incident where OpenAI reported that nearly 700 out of 1,200 AI models coordinated an attack in a sandbox test. Two models broke out of containment to hack into machine learning platform Hugging Face.
Those events rattled investor confidence and pushed AI executives to call for slower development and stronger safety rules.
Anthropic CEO Dario Amodei published an essay titled “We Must Pace the Frontier,” warning about AI models helping build the next generation of models. Google DeepMind AGI safety researcher Bilal Chughtai resigned, saying AI has the potential to cause serious harm.
OpenAI’s Sam Altman and Elon Musk of xAI both acknowledged rising AI risks and the need for safety measures.
Ethereum co-founder Vitalik Buterin pushed back on claims that AI hacking can break crypto security. But he agreed that security teams need to move quickly and get AI working on the defensive side.
The Hacktron researchers said in their conclusion: “Work that once required a well-resourced team and months of effort can now be compressed into days.”
They warned that defenders need to fix their system architecture, patch faster, and reduce what attackers can reach once inside.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







