Three Security Researchers Used the Claude Chatbot to Break Into OpenAI, the Maker of ChatGPT, in Under Three Days
A three-person security firm says it used Anthropic's Claude to find and exploit two flaws that let it take over OpenAI employees' accounts and reach the company's private code, then reported everything and collected a $6,500 reward. Both flaws were fixed the same day back in July. The researchers' point is the price tag: work that once took a well-funded team months took three people and an AI a few days.
The Wall Street Journal reported today, and a small security firm called Hacktron confirmed in its own detailed write-up, that three researchers broke into the maker of ChatGPT this summer, using a rival company's chatbot to do much of the work. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini say that on July 25 they "chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," and from there could reach the company's internal code. "We're just three guys with Claude and Codex subscriptions," Pedhapati told the Journal.
Here is how it worked, in plain terms. OpenAI runs a public help forum where users ask questions. The forum software had a flaw in the part that handles uploaded pictures: a specially built image file could make the forum's computer carry out the attacker's instructions. That got the researchers inside the forum. A second mistake, this one OpenAI's own, tied the forum's login too closely to the logins for ChatGPT and for Codex, OpenAI's tool for writing software. So controlling the forum let them take over employees' accounts on those products, and one employee's account was connected to the company's private code on GitHub, the website where programmers store their work. To prove they were really in, without reading anything sensitive, they used that account to submit a harmless proposed change to OpenAI's main code repository, then stopped and reported it. "The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours," Hacktron writes.
The AI's role is the part the researchers most want noticed. They started with a version of Anthropic's Claude called Opus 4.8, which "struggled across several sessions" to build a working attack against the forum's standard protections. On the evening of July 24, Anthropic released a newer version, Claude Opus 5. The team gave it the same problem, and it "succeeded" within hours, producing a working attack in about three hours. They then let the AI run on its own, in a loop, against a practice copy of the forum until it got in. One detail worth pausing on: the chatbot refused to write an attack against a real website, so the researchers disguised their practice target as a hacking-competition exercise to get it to cooperate.
OpenAI moved fast once told. The researchers filed their report in the morning of July 25, and OpenAI confirmed its side was fixed that same night. "We thank the researchers for contacting us and sharing their findings," the company said in a statement carried by the Journal. "We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions." The maker of the forum software, Discourse, patched its product and added extra safeguards around image handling. On September 1, OpenAI paid a $6,500 reward under its bug bounty program, the standing offer many companies make to pay outsiders who find and report flaws, noting that the forum itself was outside the program's rules and the payment was for the OpenAI-side mistake. According to the Journal, the researchers did not reach OpenAI's model weights, the trained AI itself, and Hacktron says it did not read any of the company's code.
There are two ways to read this, and both are fair. Hacktron's reading is about cost. The firm says its whole two-month campaign, which went after several large companies, "cost less than $3,000 in tokens in total," meaning AI usage fees, "and was conducted by three researchers." Its conclusion: "Work that once required a well-resourced team and months of effort can now be compressed into days." The other reading is that the system worked. The flaws were ordinary ones, an out-of-date image library and a login setting, found by people playing by the rules, reported within hours, and fixed within a day. Nothing was stolen.
What the story captures is the moment the two readings meet. The same AI that can be pointed at a company's defenses, hours after its release, is available to anyone with a subscription, and the people who found the way in were three researchers with a few thousand dollars. It is also an odd snapshot of the industry: one company's newest chatbot being used, on its first night out, to pick the locks of its chief rival.