Security Researchers Used Claude to Reach OpenAI Systems Through a Forum Authentication Flaw

Image: Ars Technica AI
Main Takeaway
Security researchers used Anthropic’s Claude to exploit OpenAI’s forum sign-on system, reach an employee account and access sensitive GitHub data before OpenAI fixed the flaws.
Jump to Key PointsSummary
What the researchers accessed
Security researchers used Anthropic’s Claude to exploit weaknesses in OpenAI’s community forum infrastructure, reach an OpenAI employee’s ChatGPT account and access sensitive GitHub data. The attack path ran through the forum’s third-party Discourse setup, then connected internal sign-on access to an employee account with permissions extending into OpenAI’s code repositories, according to the incident accounts.
OpenAI said it fixed the issues and thanked the researchers for reporting them. The disclosure describes an authorized security test rather than a destructive intrusion, but the route matters because it linked a public-facing community service to privileged internal resources. Ars Technica provided the clearest account of the forum, sign-on and GitHub sequence, while The Guardian and Forbes characterized the event as an ethical hack.
How Claude shaped the attack
Claude served as an operational assistant for the researchers, helping them work through the attack chain rather than acting as an autonomous intruder that independently selected and compromised OpenAI. Coverage describes a small team using Anthropic’s model to identify weaknesses, connect separate steps and reach systems that held internal information.
The use of a rival company’s model gives the incident unusual competitive weight. OpenAI’s systems were tested with Claude, while Anthropic’s model became part of the workflow used to expose the weaknesses. VentureBeat identified Claude Opus 5 in its account, and Fortune reported that OpenAI paid a $6,500 bug bounty for the findings. Those details frame the case as a paid disclosure involving model-assisted security research, not a confirmed theft of proprietary code for criminal use.
The identity and scope of the breach
The researchers were described in several accounts as a small team, with The Tech Portal identifying them as 3 Indian researchers who completed the work in under 72 hours. The available details center on access to an employee account and internal GitHub data, rather than a broad compromise of OpenAI’s entire infrastructure.
Headlines using terms such as “hacked” and “broke into OpenAI” compress a more specific sequence of security failures. The reported chain began with the community forum, moved through internal sign-on mechanisms and ended at an account with code access. OpenAI’s response confirms remediation, while the published accounts do not establish that attackers changed production systems, stole customer data or obtained all of OpenAI’s source code.
Why the incident matters for AI security
The incident shows how an AI model can reduce the time and effort needed to coordinate a multi-step vulnerability investigation. A forum configuration flaw, credential pathway and excessive account permissions each represented a separate security concern; together, they created a route into sensitive developer resources. That structure makes identity boundaries and third-party services as important as model safeguards.
The disclosure also lands amid broader warnings about models performing offensive security tasks. Reuters and The Independent linked the OpenAI incident to Anthropic’s disclosures about AI systems engaging in hacking activity during testing, while the BBC reported on the use of fake profiles in an Anthropic-related hacking case. SecurityWeek separately highlighted flaws in Claude Code that exposed developer devices to silent attacks. These incidents concern different systems and behaviors, but together they show why AI-assisted security testing requires strict authorization, logging and access controls.
What companies should change
Companies using AI in security work need controls around both the model and the human accounts it assists. The OpenAI case points to practical priorities: isolate community platforms from internal authentication, apply least-privilege permissions to employee accounts, audit GitHub access and monitor unusual movement between services. Bug-bounty programs also need clear boundaries for testing identity systems and third-party integrations.
Model providers face a parallel responsibility. Claude helped researchers move through a real attack chain, showing the value of capable cyber assistance in defensive work and the risk when similar capabilities reach unauthorized operators. OpenAI’s patch and bounty address the reported weaknesses, while Anthropic’s broader testing disclosures place the episode inside a larger debate over how models should handle exploit discovery, credential use and social engineering.
What happens next
The immediate outcome is remediation: OpenAI fixed the reported issues and paid a $6,500 reward, according to coverage of the disclosure. The longer-term test is whether OpenAI and other AI companies can prevent comparable paths through partner-hosted services, employee accounts and code repositories.
Security teams will also track how model providers define acceptable cyber assistance. The case gives defenders a concrete example of AI accelerating vulnerability research without evidence in the published accounts of a production outage or customer compromise. It also gives attackers a repeatable pattern to study, making identity segmentation, permission reviews and rapid disclosure response central to the next phase of AI security.
Key Points
OpenAI fixed forum and account flaws after researchers used Claude to reach sensitive GitHub data.
Claude helped coordinate an authorized attack chain linking Discourse, sign-on access and an employee account.
OpenAI paid researchers a $6,500 bug bounty for reporting the vulnerabilities.
The incident exposed risks created by weak separation between community platforms and internal code systems.
Anthropic’s model-assisted hacking case adds pressure for stronger AI cyber-use safeguards.
Questions Answered
Researchers used Claude to help identify and connect weaknesses in OpenAI’s community forum, sign-on systems and employee access. The chain reached an OpenAI employee’s ChatGPT account, which had access to sensitive GitHub data.
Published accounts confirm access to sensitive GitHub data, but they do not establish unrestricted theft of all OpenAI source code. The activity was described as an authorized ethical hack reported through OpenAI’s bug-bounty process.
OpenAI paid the researchers a $6,500 bug bounty for reporting the vulnerabilities. OpenAI also said it fixed the issues and thanked the researchers for sharing their findings.
OpenAI’s third-party community forum setup helped expose a path into internal sign-on access and an employee account. That account had permissions reaching GitHub data, showing how connected services and excessive privileges compounded the risk.
The OpenAI incident shows that Claude can accelerate authorized multi-step vulnerability research against real systems. It also highlights the need to separate public forums, identity infrastructure, employee accounts and source-code repositories.
OpenAI has fixed the reported flaws, while security teams will examine identity segmentation, account permissions and third-party service connections. AI companies also face pressure to define safer boundaries for model-assisted cyber operations.
Source Reliability
38% of sources are highly trusted · Avg reliability: 72
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems