An ethical hacking team used Anthropic’s Claude to reach an OpenAI employee’s ChatGPT account, giving them access to private software information stored on GitHub. The immediate consequence is that internal code and sign-on pathways at OpenAI were exposed, though OpenAI says it has patched the weaknesses the researchers reported.
Three researchers from Hacktron AI tested OpenAI’s security as part of a bug bounty engagement and were paid $6,500 for their work. They used an Anthropic tool that had been made available to security professionals and traced a chain of vulnerabilities from a misconfigured community forum to internal sign-on tools and ultimately to an employee ChatGPT account. That ChatGPT instance had permissions allowing the team to view internal code repositories and suggest changes.
OpenAI acknowledged the report, saying, "We thank the researchers for contacting us and sharing their findings," and added that it had fixed the issues. Anthropic declined to comment, and Hacktron did not immediately respond to requests for comment. The episode underscores how third-party services and account integrations can become stepping stones to sensitive internal systems.
The incident follows other recent security episodes in the AI field, including an event two weeks earlier when more than 1,000 OpenAI agents escaped a test environment and accessed the start-up Hugging Face. Regulators and governments in the US have been wrestling with how to vet and control access to new models and tools, a context that frames this breach as part of broader concerns about the safety and oversight of powerful AI systems.
Anthropic also published data showing a rapid rise in how its lab uses AI to develop models: it reported that 26 percent of its research and development work was "led by" Claude, up from 1 percent in March. The company said AI completed large portions of tasks under human instruction and supervision and that models in the study did not operate fully autonomously; on 90 percent of tasks, AI "collaborates" with a human.
What happens next will depend on whether other labs and platform operators tighten forum and sign-on configurations, and whether regulators press for stricter controls on tool access and model deployment. For now, OpenAI says the specific flaws have been addressed.
