Claude Didn't Break OpenAI. Three Researchers Did, in 72 Hours.
Researchers at the cybersecurity startup Hacktron used Anthropic's Claude to chain an image-processing flaw with a weakness in OpenAI's identity layer, reaching employee accounts and an internal code repository in under 72 hours. The technical details are still thin, but the compliance questions are already piling up.
Three people. One competitor's AI model. Under 72 hours to get from a public-facing endpoint to OpenAI's internal source control.
That's not a movie plot. That's what researchers at the cybersecurity startup Hacktron pulled off in July, and it should make every security team at every AI lab pay attention.
What Happened
The Hacktron team chained two flaws together. One was an image-processing vulnerability. The other was a weakness in OpenAI's identity infrastructure. Neither one, on its own, gets you very far. Chained, they got the researchers into multiple employee accounts across ChatGPT and Codex.
Then came the pivot. One of those compromised Codex accounts was tied to OpenAI's GitHub, which is the doorway to an internal code repository. That's the part that matters here. Not the ChatGPT access, which is embarrassing but recoverable. Source code is the family jewels.
Anthropic's Claude was part of the toolchain. Reading between the lines, the model did what a capable junior researcher does, grinding through reconnaissance, pattern matching and exploit iteration at machine speed. The exact division of labor isn't public yet. Notably, nobody has published a full technical writeup, or at least not the version I'd want to read.
Also missing: whether OpenAI authorized the work in advance. Bug bounty, or no permission? That single detail changes how this whole story gets characterized, and probably how it gets litigated.
Why It Matters
Identity is the soft underbelly of every AI company. Not the model weights, not the GPU cluster, the login layer. OpenAI runs one of the largest consumer identity systems on the planet, with ChatGPT accounts, API keys, Codex sessions and enterprise SSO all feeding the same graph. Every one of those connections is a possible pivot point.
Here's the uncomfortable part for Anthropic. Its own model was reportedly the assist on a breach of its chief competitor. That's not a moral failing on Anthropic's part. That's just what dual-use technology looks like. Every frontier lab is selling the same capability to defenders and attackers at the same time, and no one has figured out how to meter that.
So ask the obvious question. If three people with a rented model can get from a public image endpoint to internal Git in under 72 hours, what does that mean for a company with 5,000 engineers and a decade of accumulated access sprawl?
From a compliance standpoint, the window just got shorter for everyone. Incident response playbooks that assumed a two-week dwell time are fiction now. Sixty hours is the new normal, and most security teams can't even get their logs correlated in that time.
Who benefits? Hacktron, obviously, which just earned the best marketing it will ever get for free. Bug bounty programs, which get cheaper when AI does the grunt work. And the labs selling security copilots, who now have a case study with real numbers attached.
Who loses? Anyone treating the identity layer as a solved problem.
What to Watch
Three things. First, whether OpenAI confirms a patch and how fast it moved after July. Second, whether the flaws get CVE numbers, because that tells you how the industry is classifying them, and classification drives budget.
Third, and most interesting to me, whether this reaches federal regulators. OpenAI isn't public, so the SEC's 2023 cybersecurity disclosure rules don't reach it directly. But its partners are public companies, and materiality tests don't care about legal structure. What regulators are really signaling: an AI-assisted breach of a major AI lab, disclosed quietly, is exactly the kind of test case that shapes enforcement for years.
The precedent here's important, and it's being written right now, in real time, by three researchers and a model that wasn't supposed to be the story.
So watch the disclosure, not the drama. That's where the real story lives.
Related Articles
Explore More
Key Terms Explained
A reward offered by crypto projects for completing specific tasks like finding bugs, writing code, or creating content.
A reward program where protocols pay security researchers for finding and responsibly disclosing vulnerabilities.
Following the laws and regulations that apply to financial activities, including crypto.