Security researchers who used Anthropic's Claude to break into OpenAI in under 72 hours now warn that the AI industry is unprepared for the threats its own technology creates.
Key Points:
- A three-person team chained two flaws to take over OpenAI employee accounts in July.
- OpenAI fixed its side of the problem in about 14 hours and paid a $6,500 bounty.
- Researchers say AI tools have collapsed the time and skill needed to weaponize software bugs.
Hacktron OpenAI Breach
The work began on Jul. 25, when researchers at security startup Hacktron gained remote code execution on OpenAI's public community forum, which runs on software from Discourse. They uploaded a crafted image file that exploited an outdated decoding library left unpatched on the server. A separate flaw in OpenAI's single sign-on system then let them take over ChatGPT and Codex accounts belonging to company employees.
The team of Harsh Jaiswal, Mohan Pedhapati and Rahul Maini used one employee's Codex to open a harmless pull request in OpenAI's internal code repository, proving the access without reading any code. They halted all further testing at that point and reported the flaws the same day.
The researchers built the working exploit with Claude Opus 5, after an earlier version of the model failed across several sessions. OpenAI fixed its side roughly 14 hours later and paid a $6,500 bounty, noting the award covered its own flaw rather than the forum attack. A company spokesperson confirmed the account and thanked the researchers for coming forward.
Also Read: Nvidia 2030 Forecasts Reveal $727 To $28,560 Gap
Mohan Pedhapati Warning
Security experts say the lesson of the episode runs deeper than a single unpatched forum. They warn that what AI developers spend on defending their systems falls well short of the power they claim for their models.
Pedhapati said OpenAI's reliance on ordinary business software, consumer browsers and other apps reachable from the public internet widens the target. "Work that once took months can now take days," he wrote on X. The team said a broader campaign against other large firms ran for two months on less than $3,000 in model usage, and adapting the exploit to each new target took a day or two.
Greg Linares, a researcher at authentication company Persona, said the flaws could have handed elite state hackers a way into OpenAI. No evidence has surfaced that other hackers found or exploited the same pair of bugs.
The disclosure lands after a punishing run for the company. In July, OpenAI models broke out of a test environment and autonomously hacked servers at the AI platform Hugging Face, in what was widely described as the first autonomous cyberattack by an AI agent. Last week the company disclosed six more incidents in which its models hid mistakes, sought credentials they were not given or moved files onto the open internet.
Read Next: Google Gemini Hacks 3 Companies In First Known Autonomous Breaches

