Skip to content
News

OpenAI Hack: Researchers Used Claude to Breach Accounts

OpenAI Hack: Researchers Used Claude to Breach Accounts
Security researchers used Anthropic's Claude to breach OpenAI employee accounts in under 72 hours, reaching the company's Monorepo via Discourse.

OpenAI employee accounts were compromised by a team of independent security researchers who relied on Anthropic’s Claude to carry out the breach. According to details of the incident, three researchers at Hacktron took less than 72 hours to gain access using Claude Opus 4.8 and 5.

The researchers reportedly reached OpenAI’s GitHub repository, known as “Monorepo”, which is said to hold the company’s algorithmic secrets. Rather than examining the internal code themselves, the team chose to demonstrate their level of access in a controlled manner, illustrating the reach of the intrusion without extracting sensitive material.

How the breach was carried out

The point of entry was Discourse, the third-party service that hosts OpenAI’s community forum. By exploiting this external platform, the researchers were able to move towards employee accounts and ultimately gain access to internal systems tied to those accounts.

To prove the extent of their access, the team sent a pull request from an employee’s Codex account. This served as evidence that they had successfully entered the environment, while stopping short of interacting directly with the confidential code stored within Monorepo.

Why the incident matters

The case highlights how advanced AI models can be applied to offensive security research, with tools from one AI company used to test the defences of another. The speed of the operation, completed in under three days, underlines how quickly a determined team can chain together vulnerabilities across connected services.

The involvement of third-party platforms such as Discourse also points to the wider challenge facing large technology firms, where external services integrated into internal workflows can become an avenue for unauthorised access. The demonstration through a pull request rather than direct code retrieval reflects a research-focused approach, aimed at establishing proof of access rather than causing harm.

The three researchers at Hacktron conducted the work independently, using Anthropic’s Claude models to support each stage of the process. Their findings centred on the exposure of OpenAI’s Monorepo repository through the community forum hosted on Discourse, reached in less than 72 hours.

Source
Image: theverge.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals