• Economy
  • Editor’s Pick
Money Rise Today – Investing and Stock News
  • Investing
  • Stock
Investing

Claude helped hackers get inside OpenAI, but the real shock came next

by September 18, 2026
written by September 18, 2026

Anthropic’s Claude helped a three-person security team penetrate OpenAI’s systems in July, according to an exclusive report by The Wall Street Journal, but the most consequential part of the episode came after the initial exploit.

Researchers at Hacktron AI first broke into the Discourse software that powers OpenAI’s community forum by exploiting a flaw in how it processed uploaded images.

That gave the researchers an initial foothold, but the breach became more serious when they combined it with a separate weakness in OpenAI’s single-sign-on system, the technology that allows users to access multiple services with the same account.

The researchers were then able to reach ChatGPT and Codex accounts, including one belonging to an OpenAI employee.

That employee’s Codex account was connected to GitHub, the platform OpenAI uses to store and manage software code.

Through that connection, the researchers were ultimately able to demonstrate access to OpenAI’s internal GitHub organisation, significantly widening the potential impact of the original forum vulnerability.

Claude helped a team build a serious exploit chain

Hacktron’s researchers began by examining how Discourse processed HEIC and HEIF uploads.

The route exposed the libheif image decoder through ImageMagick.

Hacktron said Claude helped identify missing security backports and develop a working exploit that turned the memory-corruption bug into remote code execution against the forum environment.

The team said the full path from initial discovery to OpenAI repository access took less than 72 hours.

Mohan Pedhapati, Hacktron’s chief technology officer, captured the significance in comments to The Wall Street Journal: “We’re just three guys with Claude and Codex subscriptions.”

That does not mean Claude autonomously breached OpenAI from start to finish. Hacktron said skilled human guidance remained important.

But the episode shows how frontier coding models can compress work that once required more specialist labour, time and infrastructure.

Hacktron said the broader research campaign was carried out by three researchers and cost less than $3,000 in model tokens.

One compromised identity opened a much larger door

The bigger risk appeared after the forum compromise.

Hacktron said the breach became more serious because of a weakness in OpenAI’s single-sign-on system, rather than the Discourse forum itself.

Once the researchers gained access to ChatGPT and Codex accounts, they could potentially reach other services linked to those accounts.

In the OpenAI employee account used for the test, Codex was connected to the company’s GitHub organisation, where its software code is stored and managed.

Instead of reading proprietary source code, the researchers instructed Codex to make a harmless change and open a pull request inside OpenAI’s internal monorepo.

The initial bug affected image processing, but OpenAI’s identity architecture turned a forum foothold into access to more sensitive developer infrastructure.

OpenAI confirmed the issue had been fixed about 14 hours after the initial report, according to Hacktron. The company later paid a $6,500 bounty for the OpenAI-side finding.

Also read: OpenAI says AI cannot keep scaling at ‘maximum speed’ after six concerning incidents

AI is lowering the cost of sophisticated cyberattacks

The Hacktron team operated as white-hat researchers and disclosed what they found, but a malicious attacker would have little incentive to stop at a harmless pull request.

Anthropic said in its September threat report that it had disrupted cyber operations in which actors used Claude for reconnaissance, exploitation, malware development and data theft.

The company said AI is allowing adversaries to operate faster, across broader attack surfaces and with fewer resources.

Jack Nelson, chief information security officer and deputy general counsel at Ivanti, told Axios that “a swarm does not need to be perfect to be dangerous.”

He added that thousands of agents making merely adequate decisions at machine speed could still cause meaningful disruption.

OpenAI and Discourse fixed the vulnerabilities, making this a successful responsible-disclosure case.

But the episode leaves an uncomfortable lesson. Claude helped make exploitation cheaper and faster, while interconnected identity and developer tools widened the consequences of one compromised account.

The real risk is not simply that AI can find bugs, but that a small team can now move through a complex attack chain quickly, and the next team may have no reason to stop.

The post Claude helped hackers get inside OpenAI, but the real shock came next appeared first on Invezz

0 comment
0
FacebookTwitterPinterestEmail

previous post
Top FTSE 100 shares to watch: BP, Shell, Lloyds, Rolls-Royce, Scottish Mortgage
next post
Could GOOG stock rise by up to 40%? Search strength, AI push could make it possible

related articles

SpaceX stock forecast after hitting a $946 million...

September 18, 2026

Evening digest: Aramco to halt Europe oil deliveries,...

September 18, 2026

Dow closes 110 pts lower as treasury yields...

September 18, 2026

Micron stock rises as RBC sees AI memory...

September 18, 2026

BMO recommends betting on a recovery in this...

September 18, 2026

Why is SanDisk stock gaining 8% today?

September 18, 2026

BitMine stock is stuck in neutral: here’s why...

September 18, 2026

Accenture stock falls 4% today: here’s why

September 18, 2026

Volkswagen stock plunges as €10B hit forces 2026...

September 18, 2026

Warren Buffet steps down as chairman: what happens...

September 18, 2026
Enter Your Information Below To Receive Free Trading Ideas, Latest News, And Articles.


Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

Latest News

  • Here’s why Samsung, SK Hynix, and Kioxia stocks are diving today

    July 2, 2026
  • Micron stock falls 3% as Taiwan unions threaten strike over bonuses

    September 1, 2026
  • Apple price hikes unlikely to hurt demand, JPMorgan says as it raises PT

    July 8, 2026
  • Solidion stock announces space pivot ahead of SpaceX IPO: but will the gains last?

    June 4, 2026
  • Strategy (MSTR) stock falls 5% as Clarity Act stalls

    September 15, 2026

Popular Posts

  • 1

    CoreWeave stock jumps 10% as analysts see major backlog upside

    June 16, 2026
  • 2

    Intel, AMD stocks slide again in aftermath of Broadcom’s weak outlook

    June 5, 2026
  • 3

    Dow tumbles 680 points as chip rout sends Nasdaq to biggest drop since 2025

    June 5, 2026
  • 4

    Wedbush makes a strong case for buying the dip in Planet Labs stock

    June 5, 2026
  • 5

    Wedbush makes a strong case for buying the dip in Planet Labs stock

    June 5, 2026

Categories

  • Editor's Pick (626)
  • Investing (1,361)
  • Stock (90)

Latest Posts

  • Micron stock jumps 7% as AI memory demand fuels supercycle optimism

    June 15, 2026
  • Palantir stock is stuck in a bear market: Here’s why it may rebound soon

    July 14, 2026
  • Anthropic IPO will benefit these two mega-cap stocks

    September 16, 2026

Recent Posts

  • Best trading platforms to buy SpaceX stock (SPCX)

    June 12, 2026
  • Jack Smith’s Senate phone records probe turns to Verizon’s handling of subpoenas

    August 1, 2026
  • GOP blocks Schumer’s effort to ground taxpayer funding for Trump’s Qatari Air Force One

    July 22, 2026

Editor’s Pick

  • Nvidia, Palantir team up to build ‘Sovereign AI’ for supply chains

    September 10, 2026
  • Evening digest: Moonshot causes AI selloff, Apple retakes top market cap crown

    July 17, 2026
  • Nvidia, AMD and Intel stocks are crashing: here’s why this selloff is different

    September 14, 2026
  • About us
  • Contacts
  • Privacy Policy
  • Terms & Conditions

Disclaimer: moneyrisetoday.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

Copyright © 2025 moneyrisetoday.com | All Rights Reserved

Money Rise Today – Investing and Stock News
  • Economy
  • Editor’s Pick
Money Rise Today – Investing and Stock News
  • Investing
  • Stock