White-Hat Hackers Compromise OpenAI in Under 3 Days With Claude AI

September 27, 2026

A few months ago, cybersecurity experts managed to breach OpenAI’s internal systems and gain access to employees’ ChatGPT accounts in under 72 hours. It was an ethical hacking operation that involved Claude, Anthropic’s AI. Why undertake such an operation? How did it unfold?

An intrusion via OpenAI’s internal messaging platform

Founded in the United States in 2025, the startup Hacktron AI specializes in AI-powered cybersecurity. It positions itself on the market as a true virtual security engineer (or an “AI teammate”) for developers. Hacktron AI offers an automated platform for intrusion testing and code review. The goal? To help companies secure their applications at a lower cost and to receive vulnerability reports in just a few hours.

In a blog post published on September 13, 2026, Hacktron AI explained that it had conducted an ethical hacking operation against OpenAI three months earlier. According to the engineers, this operation illustrates how artificial intelligence is transforming the speed and accessibility of cyber intrusions.

Experts say they targeted the Discourse messaging platform, used internally by OpenAI. This platform allowed employees to connect directly to their professional ChatGPT accounts or Codex, OpenAI’s coding-assistance tool. Yet Hacktron AI’s specialists identified a vulnerability in this authentication system, before gaining direct access to employees’ internal accounts.

How Claude was used?

The distinctive aspect of this ethical breach lies in the use of Anthropic’s Claude AI, OpenAI’s main direct competitor. In practice, Hacktron AI’s researchers submitted portions of code to Claude to have it analyze the target’s infrastructure. The AI then drafted a tailored attack script to exploit the well-known vulnerability. With this assistance, the entire operation took less than 72 hours. Normally, such an initiative would have required weeks of work and substantial resources, given that Hacktron AI’s team consists of only three people.

Since it was an ethical hacking operation, the events unfolded within a strict framework. Indeed, after unlocking private source code and internal accounts, the experts immediately alerted OpenAI. The company thus reviewed the proof of concept before awarding Hacktron AI a $6,500 reward under its Bug Bounty program.

“To demonstrate the impact of the vulnerability without accessing internal code, we sent a prompt to an employee’s Codex account so that they would open a pull request in OpenAI’s internal monorepo. We then terminated our tests.”, reads the blog post.

Toward rapid development of defensive AIs

Undoubtedly, Hacktron AI’s ethical hacking demonstrates that AI drastically lowers the entry barrier for cyberattacks. In its communications, the startup summarized the situation by explaining that now, complex operations that once required considerable expertise and time are within reach of tiny outfits armed with a subscription to a consumer-grade AI. This evolution should naturally push cybersecurity players to accelerate the deployment of defensive AIs in order to patch existing vulnerabilities as quickly as possible, ideally before they are discovered.

Sindre Halvorsen

I write about space exploration, frontier science and the technologies that are quietly shaping the future. From Norway, I follow the missions, discoveries and ideas that connect life on Earth with what lies beyond it. My goal is to make complex subjects clear, useful and worth paying attention to.