A man stands below a large Salesforce OpenAI sign at a technology conference booth
An OpenAI booth at the Dreamforce technology summit in San Francisco on Thursday. Photograph: Carlos Barría/Reuters
An OpenAI booth at the Dreamforce technology summit in San Francisco on Thursday. Photograph: Carlos Barría/Reuters

OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot

US cybersecurity researchers who conducted hack say ‘scope of what we could theoretically access was huge’

Cybersecurity researchers have hacked into OpenAI with the help of Anthropic’s Claude chatbot, in the latest example of security issues at the company.

A team at a US-based startup compromised multiple OpenAI employees’ ChatGPT accounts, starting a process that enabled them to access their target’s software cache – and potentially more.

“The scope of what we could theoretically access was huge,” said researchers at Hacktron AI.

Initially, the research team used Claude, which can generate code for hackers, to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform. They then made a harmless “pull request” – an attempt to change the code in a file – to OpenAI’s service on the GitHub software repository.

Hacktron reported the hack to OpenAI, having carried out the probe under an OpenAI programme that rewarded ethical hackers for testing its systems. The researchers stressed that they had access to, but did not download, the code from the GitHub repository.

Despite initial use of Claude, the researchers said they were largely using OpenAI’s own cutting edge GPT-5.6 Sol model to carry out the hack.

The Wall Street Journal first reported the latest OpenAI security incident.

An OpenAI spokesperson said “we thank the researchers for contacting us and sharing their findings”, adding that the company had addressed the vulnerabilities that had been exploited.

Hacktron said AI tools had made a once-complex hacking task far easier and drastically shortened the time needed to plan and execute an attack – a common refrain from cybersecurity experts when discussing the impact of AI.

“Work that once required a well-resourced team and months of effort can now be compressed into days,” said Hacktron, which received a $6,500 payment from OpenAI under the company’s bug bounty programme – a scheme under which ethical hackers receive rewards for reporting vulnerabilities.

The hack is the latest safety incident at OpenAI, which revealed in July that a “swarm” of agents – the term for AI tools capable of carrying out tasks autonomously – powered by its technology had hacked the AI startup Hugging Face during a cybersecurity test.

This week the San Francisco-based company revealed six more examples of “unexpected or concerning” behaviour by its technology, as it warned that the pace of development could not continue at “maximum speed for much longer”.

OpenAI made the fresh security revelation after Anthropic’s renewed call at the weekend for a slowdown in AI development, which was supported by the ChatGPT maker as well as Google DeepMind and Elon Musk. Anthropic also repeated warnings that unrestrained AI development posed an existential threat – concerns that some experts are sceptical about.

Donald Trump has rejected calls for a slowdown, citing a need to stay ahead of China’s AI industry and dismissing “negative forces … bringing up things that won’t happen”.