Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours

Three researchers using Anthropic’s Claude sped up an OpenAI breach to under 72 hours by chaining an image-processing flaw with an identity-infrastructure flaw, gaining access to multiple employees’ ChatGPT and Codex accounts and an internal GitHub-connected repository. Although human guidance remained essential and AI-assisted coding agents expanded reach, OpenAI fixed the identity flaw within hours, and the researchers demonstrated how compromised accounts can expose integrated services like GitHub, Slack, and email.
Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours Image by CryptoSlate # Anthropic’s Claude helped 3 researchers breach OpenAI in under 72 hours Hacktron reached OpenAI’s internal software environment after compromising a Codex account connected to GitHub. By Oluwapelumi Adejumo Senior Reporter • CryptoSlate Sep. 19, 2026 ## Quick Take 1. 01 Claude helped researchers chain two flaws into OpenAI accounts and an internal repository within 72 hours. 2. 02 AI compressed exploit development from months to days, though skilled human guidance remained essential. 3. 03 Connected coding agents concentrate permissions, letting one compromised account expose tools such as GitHub. Anthropic’s Claude helped three security researchers breach OpenAI accounts and reach an internal code repository within 72 hours. Researchers at cybersecurity startup Hacktron chained an image-processing vulnerability with a flaw in OpenAI’s identity infrastructure in July to gain access to multiple employees’ ChatGPT and Codex accounts. One compromised Codex account was connected to OpenAI’s GitHub organization, giving the researchers a path into the company’s internal software environment. The team stopped after instructing the compromised employee’s Codex account to create a harmless pull request inside OpenAI’s private `openai/openai` monorepo. Hacktron said the researchers did not inspect proprietary source code. This week, Hacktron disclosed the vulnerabilities and ended further testing. OpenAI reportedly fixed the identity-side flaw roughly 14 hours after receivin…
the newsroom’s read
Strong tech novelty with a memorable AI exploit narrative and clear imagery, scored well for a launch.
Proof sheet
- name
- Hacktron Claude
- ticker
- $CLAUDE
- description
- Anthropic's Claude helped three researchers breach OpenAI in under 72 hours, chaining image-processing and identity flaws, according to CryptoSlate.
Skip to the front page