Hackers Accessed OpenAI’s Code Using Rival Anthropic’s Claude

Hackers Accessed OpenAI’s Code Using Rival Anthropic’s Claude

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
22. 9. 2026
4 minutes reading · 3 views
Listen to the article
Audio version of the article
Hackers Accessed OpenAI’s Code Using Rival Anthropic’s Claude

At the end of July, three people from the security company Hacktron AI gained access to OpenAI's internal systems. They started with an ordinary photo uploaded to a discussion forum and ended up in the company's source code repository, where they had write access. They were aided by Claude, a tool from Anthropic, which is a direct competitor to OpenAI. They published the entire process last Thursday, OpenAI paid them $6,500 for the discovery, and the vulnerabilities have since been patched.

From a Photo on a Forum to Company Code

The way in led through OpenAI's public discussion forum. Anyone can upload an image there, and the forum automatically converts it into a common format so that it displays properly. The flaw was hidden in this conversion process. When the researchers uploaded a specially modified photo in the format commonly used by iPhones, the image-processing program became confused, allowing them to gain control of the server on which the forum was running. What made matters worse was that the creators of the program had fixed the flaw several months earlier. However, no one had officially entered it into the public database of security vulnerabilities monitored by the entire industry. This was probably why the forum continued to run an old, vulnerable version.

Once inside, the team encountered a second problem. A forum login was also valid for ChatGPT and the Codex developer tool, making it possible to take over other people's accounts, including employee accounts. In this way, they gained access to the account of an OpenAI employee who had connected Codex to the company's code repository on GitHub. There, they found a section called Monorepo. According to Wall Street Journal sources, it is a component that helps OpenAI's models run faster. The researchers did not download anything; they only submitted a harmless proposed code change to the repository to demonstrate how far they had gotten. They said that the scope of what they could theoretically have accessed was enormous. According to them, fewer than 72 hours passed between the initial breach and the confirmation of access.

They then called OpenAI and the forum operator. A fix was released on July 27. OpenAI spokesperson Drew Pusateri said that the company thanked the researchers for reaching out and sharing their findings, and that the issue had been resolved. OpenAI also invalidated the affected login sessions and restricted their permissions.

The Weaker Model Failed, but the Newer One Succeeded

The researchers worked with a special version of the Claude Opus 4.8 model that Anthropic makes available only to vetted security experts. However, the model repeatedly failed. They described how, despite repeated attempts, it struggled in vain to produce working code that could exploit the flaw. The breakthrough came overnight when Anthropic released Opus 5. The team gave it exactly the same task, and within a few hours it was done. They noted that each new model is becoming increasingly capable.

According to their report, the actual breach of OpenAI required a few days of work by a computer assistant and only a few hours of human time. It was not an attack, but part of a program in which OpenAI pays for reported vulnerabilities. It was part of research that Hacktron called HEIF Heist, in which it examined how various services handle image files. Using the same method, it also found vulnerabilities at Slack, Zoom, Meta, and other companies. The work took two months, involved three people, and cost them less than three thousand dollars in total for model usage.

Why the Media Made It a Major Story

The appeal of the story lies mainly in the balance of power. Three people with an ordinary subscription gained access to a company that develops artificial intelligence itself and certainly has money for security.

Matt Fredrikson, head of the security company Gray Swan, summed it up by saying that for two hundred dollars a month, anyone can use these tools and break into a company like OpenAI. He added that if it can happen to them—and he does not think they have been neglecting security lately—it can happen to anyone. A natural question then appeared on social media: if a three-person team can do this, what can a state or a large organization accomplish?

Hacktron founder Mohan Pedhapati wrote on X that artificial intelligence reduces the amount of scarce expertise needed for someone to exploit a vulnerability, and that work that used to take months now takes days. At the end of its report, the team wrote that software had long been protected by its own complexity, and that artificial intelligence is now dismantling that protection by replacing expertise with computing power.

The case also affected the debate over what should and should not be made publicly available. Opus 5, which ultimately cracked the vulnerability, was not subject to any export restrictions. Its newer sibling Mythos 5 was treated differently, however: US authorities temporarily blocked it precisely because of concerns about how well it performed at finding vulnerabilities in other systems. Nor does this apply only to closed models. The nonprofit organization SaferAI recently found that the freely available GLM-5.2 model from the Chinese company Z.ai trails OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7 by only a few months.

Sources: techcrunch.com, theguardian.com and forbes.com

Advertisement

Content created with help from UpTier.

SEO and GEO on autopilot. UpTier’s multi-agent systems write and optimize content for search engines and AI answers.

Discover UpTier ↗

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Trump Launches “AI Force” and Plans to Appoint an AI CzarTrump Launches “AI Force” and Plans to Appoint an AI Czar
Trump wants to accelerate AI development further, launching an AI Force and creating a new government czar position. What exactly they will do remains unclear.
4 min read
22. 9. 2026
AI godfather warns US: perhaps just one year left to regulate artificial intelligenceAI godfather warns US: perhaps just one year left to regulate artificial intelligence
Geoffrey Hinton warns that AI is starting to improve itself, and Congress may have just one year left to set rules before losing control of its rapid development.
5 min read
22. 9. 2026
Anthropic Has Built a Biology Lab. One Day, AI Could Run Experiments ThereAnthropic Has Built a Biology Lab. One Day, AI Could Run Experiments There
Claude’s creator is venturing into real-world biological experiments. Its ambition is to teach AI to operate laboratory equipment and accelerate research.
5 min read
21. 9. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok