the wire · #ai · 2026-09-18
Security researchers used Claude to help them hack into OpenAI
Cech Tech Reviews

A team from Hacktron used Anthropic's Claude Opus 4.8 and 5 to break into OpenAI employee accounts in less than three days, according to the Wall Street Journal. They gained access to OpenAI's main GitHub repository, known as Monorepo, which sources say contains the company's core algorithmic secrets.
The researchers didn't pull actual code, but they proved their access by sending a pull request from a compromised employee Codex account. Their entry point was Discourse, the third-party platform that hosts OpenAI's community forums, showing how perimeter security often fails at the integration layer, not the core product.
The bigger story here is what it signals about AI-assisted hacking. Claude wasn't just a research assistant. It actively helped identify vulnerabilities, craft exploits, and navigate OpenAI's systems fast enough to breach a top AI lab in a long weekend. That's a capability shift, not just a speed improvement.
This also highlights the brittleness of third-party integrations in the AI stack. OpenAI's own systems might be locked down, but Discourse became the weak link. As AI companies race to ship features and collaborate across platforms, the attack surface grows faster than security teams can cover it.
For OpenAI, this is more than embarrassing. It's a preview of the adversarial future where your competitor's AI helps people probe your defenses. Expect this to accelerate the already tense conversation around model safety, red-teaming, and whether frontier AI should have built-in restrictions against offensive security work.
What this means for you: if you're building with AI APIs or managing teams using them, audit your third-party integrations now. The tools your team uses to collaborate, like forums, ticket systems, or code hosts, are increasingly the entry point for attacks. Try this with your AI assistant: "List all third-party services integrated with our main product, then for each one, identify what level of access it has and what data it could expose if compromised." It's a faster way to map your real attack surface than waiting for a pentest report.
Reporting basis: original story
← back to The Wire







