• Economy
  • Editor’s Pick
Money Rise Today – Investing and Stock News
  • Investing
  • Stock
Investing

Claude helped hackers get inside OpenAI, but the real shock came next

by September 18, 2026
written by September 18, 2026

Anthropic’s Claude helped a three-person security team penetrate OpenAI’s systems in July, according to an exclusive report by The Wall Street Journal, but the most consequential part of the episode came after the initial exploit.

Researchers at Hacktron AI first broke into the Discourse software that powers OpenAI’s community forum by exploiting a flaw in how it processed uploaded images.

That gave the researchers an initial foothold, but the breach became more serious when they combined it with a separate weakness in OpenAI’s single-sign-on system, the technology that allows users to access multiple services with the same account.

The researchers were then able to reach ChatGPT and Codex accounts, including one belonging to an OpenAI employee.

That employee’s Codex account was connected to GitHub, the platform OpenAI uses to store and manage software code.

Through that connection, the researchers were ultimately able to demonstrate access to OpenAI’s internal GitHub organisation, significantly widening the potential impact of the original forum vulnerability.

Claude helped a team build a serious exploit chain

Hacktron’s researchers began by examining how Discourse processed HEIC and HEIF uploads.

The route exposed the libheif image decoder through ImageMagick.

Hacktron said Claude helped identify missing security backports and develop a working exploit that turned the memory-corruption bug into remote code execution against the forum environment.

The team said the full path from initial discovery to OpenAI repository access took less than 72 hours.

Mohan Pedhapati, Hacktron’s chief technology officer, captured the significance in comments to The Wall Street Journal: “We’re just three guys with Claude and Codex subscriptions.”

That does not mean Claude autonomously breached OpenAI from start to finish. Hacktron said skilled human guidance remained important.

But the episode shows how frontier coding models can compress work that once required more specialist labour, time and infrastructure.

Hacktron said the broader research campaign was carried out by three researchers and cost less than $3,000 in model tokens.

One compromised identity opened a much larger door

The bigger risk appeared after the forum compromise.

Hacktron said the breach became more serious because of a weakness in OpenAI’s single-sign-on system, rather than the Discourse forum itself.

Once the researchers gained access to ChatGPT and Codex accounts, they could potentially reach other services linked to those accounts.

In the OpenAI employee account used for the test, Codex was connected to the company’s GitHub organisation, where its software code is stored and managed.

Instead of reading proprietary source code, the researchers instructed Codex to make a harmless change and open a pull request inside OpenAI’s internal monorepo.

The initial bug affected image processing, but OpenAI’s identity architecture turned a forum foothold into access to more sensitive developer infrastructure.

OpenAI confirmed the issue had been fixed about 14 hours after the initial report, according to Hacktron. The company later paid a $6,500 bounty for the OpenAI-side finding.

Also read: OpenAI says AI cannot keep scaling at ‘maximum speed’ after six concerning incidents

AI is lowering the cost of sophisticated cyberattacks

The Hacktron team operated as white-hat researchers and disclosed what they found, but a malicious attacker would have little incentive to stop at a harmless pull request.

Anthropic said in its September threat report that it had disrupted cyber operations in which actors used Claude for reconnaissance, exploitation, malware development and data theft.

The company said AI is allowing adversaries to operate faster, across broader attack surfaces and with fewer resources.

Jack Nelson, chief information security officer and deputy general counsel at Ivanti, told Axios that “a swarm does not need to be perfect to be dangerous.”

He added that thousands of agents making merely adequate decisions at machine speed could still cause meaningful disruption.

OpenAI and Discourse fixed the vulnerabilities, making this a successful responsible-disclosure case.

But the episode leaves an uncomfortable lesson. Claude helped make exploitation cheaper and faster, while interconnected identity and developer tools widened the consequences of one compromised account.

The real risk is not simply that AI can find bugs, but that a small team can now move through a complex attack chain quickly, and the next team may have no reason to stop.

The post Claude helped hackers get inside OpenAI, but the real shock came next appeared first on Invezz

0 comment
0
FacebookTwitterPinterestEmail

previous post
Top FTSE 100 shares to watch: BP, Shell, Lloyds, Rolls-Royce, Scottish Mortgage
next post
Could GOOG stock rise by up to 40%? Search strength, AI push could make it possible

related articles

SoundHound stock breaks key support as short interest...

October 9, 2026

Evening Digest: Oil falls, Apple cuts iPhone component...

October 9, 2026

Dow rises 423 points as tech stocks rebound,...

October 9, 2026

Coherent stock forms bullish pattern as Lumentum projects...

October 9, 2026

Snowflake stock rises 6% as AI Marketplace launch...

October 9, 2026

Democratic midterm sweep could sink US stocks by...

October 9, 2026

Joby Aviation stock slumps toward a death cross:...

October 9, 2026

SpaceX’s network plans have rattled legacy carriers, but...

October 9, 2026

Why is Tesla stock gaining today?

October 9, 2026

How OpenAI’s revenue discrepancy shook the AI stock...

October 9, 2026
Enter Your Information Below To Receive Free Trading Ideas, Latest News, And Articles.


Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

Latest News

  • SCHD nears title of biggest dividend ETF, but technical risks loom

    September 1, 2026
  • Why is SanDisk stock rising today?

    June 10, 2026
  • Column: Wall Street’s AI-fueled surge is running into resistance

    June 11, 2026
  • FTSE 250 edges up as Segro rally lifts UK property stocks

    June 24, 2026
  • SpaceX stock outlook: where will SPCX be in the next five years?

    September 16, 2026

Popular Posts

  • 1

    Intel, AMD stocks slide again in aftermath of Broadcom’s weak outlook

    June 5, 2026
  • 2

    CoreWeave stock jumps 10% as analysts see major backlog upside

    June 16, 2026
  • 3

    Dow tumbles 680 points as chip rout sends Nasdaq to biggest drop since 2025

    June 5, 2026
  • 4

    Wedbush makes a strong case for buying the dip in Planet Labs stock

    June 5, 2026
  • 5

    Wedbush makes a strong case for buying the dip in Planet Labs stock

    June 5, 2026

Categories

  • Editor's Pick (711)
  • Investing (1,779)
  • Stock (90)

Latest Posts

  • Dow futures jump 220 points: 5 things to know before Wall Street opens on Oct. 6

    October 6, 2026
  • Newly unclassified Pentagon images show suspected drug boats as official issues deadly warning

    August 31, 2026
  • US faces another major Middle East troop withdrawal, but threat remains

    September 30, 2026

Recent Posts

  • Why is Nvidia stock rising on Wednesday?

    September 30, 2026
  • Strategy (MSTR) stock slumps as Bitcoin bet and preferred shares under pressure

    June 23, 2026
  • Dow closes above 52,000 as Alphabet shines, tech stocks lift markets

    June 29, 2026

Editor’s Pick

  • Michigan Republican lawmaker warns guaranteed income programs do not work, voices opposition to state policy

    September 17, 2026
  • Shopify stock is rallying, and it has Meta Platforms to thank

    September 22, 2026
  • AMD stock surge brings $1 trillion status within reach, but key risks remain

    June 15, 2026
  • About us
  • Contacts
  • Privacy Policy
  • Terms & Conditions

Disclaimer: moneyrisetoday.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

Copyright © 2025 moneyrisetoday.com | All Rights Reserved

Money Rise Today – Investing and Stock News
  • Economy
  • Editor’s Pick
Money Rise Today – Investing and Stock News
  • Investing
  • Stock