AI tools compress months of hacking work into days, Hacktron says
Cybersecurity researchers at Hacktron AI breached OpenAI’s internal systems with help from Anthropic’s Claude chatbot, gaining access to employee ChatGPT accounts through a staff discussion forum, the researchers said Thursday. The operation was carried out under OpenAI’s bug bounty program, which rewards researchers for identifying security flaws.
The disclosure adds to a series of recent security incidents at OpenAI and coincides with renewed industry debate over the pace of AI development, including calls from major AI companies for a slowdown that President Donald Trump has publicly rejected.
The researchers initially used Claude, which can generate code for hackers, to access ChatGPT accounts via the staff forum, which is hosted on the Discourse platform. They then submitted what they described as a harmless “pull request” — an attempt to change code in a file — to OpenAI’s service on the GitHub software repository.
Hacktron said the process that began with the compromised ChatGPT accounts could have given the researchers access to OpenAI’s software cache — and potentially more — beyond what they actually used. “The scope of what we could theoretically access was huge,” the researchers said. They stressed they had access to but did not download the code from the GitHub repository.
An OpenAI spokesperson thanked the researchers for sharing their findings, adding that OpenAI had addressed the vulnerabilities that had been exploited. Hacktron received a $6,500 payment from OpenAI under the bug bounty program.
Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack — a common refrain from cybersecurity experts when discussing the impact of AI. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the company said.
Despite the initial use of Claude, the researchers said they were largely using OpenAI’s own GPT-5.6 Sol model to carry out the hack. The incident was first reported by the Wall Street Journal.
The disclosure comes two months after OpenAI revealed that a “swarm” of agents — the term for AI tools capable of carrying out tasks autonomously — powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test in July.
This week, the San Francisco-based company revealed six more examples of “unexpected or concerning” actions by its technology and warned that the pace of development could not continue at “maximum speed for much longer.”
At the weekend, Anthropic made a fresh call for a slowdown in AI development, a position supported by OpenAI, Google DeepMind and Elon Musk. Anthropic also repeated warnings that unrestrained AI development posed an existential threat, concerns that some experts are sceptical about.
President Donald Trump has rejected calls for a slowdown, citing the need to stay ahead of China’s AI industry and dismissing “negative forces … bringing up things that won’t happen.”