Security researchers at startup Hacktron AI successfully compromised OpenAI’s internal systems using rival Anthropic’s Claude AI software. The researchers gained access to an OpenAI employee’s ChatGPT account, which then provided access to the company’s internal code on GitHub. The exploit demonstrated how advanced AI models themselves can become tools for sophisticated cyberattacks against technology companies.
Hacktron participated in OpenAI’s bug-hunting program and received a $6,500 bounty for disclosing their work responsibly. OpenAI confirmed the incident and stated the company thanked the researchers and subsequently fixed the underlying vulnerabilities. However, the breach highlights escalating cybersecurity risks posed by increasingly capable AI systems.
The researchers initially attempted to use Anthropic’s Claude Opus 4.8 to construct an exploit but struggled to produce a working payload across multiple sessions. When Anthropic released Claude Opus 5, Hacktron tried again and immediately succeeded. The researchers documented that “every new model is getting increasingly capable,” suggesting that AI model improvements directly translate to enhanced attack capabilities.
Hacktron had access to a special version of Claude designed specifically for qualified cybersecurity practitioners. This version, intended to enable security research, instead facilitated the OpenAI breach. The incident raises questions about whether AI models designed for security research can be responsibly deployed without becoming weapons in adversary hands.
The breach required only days of autonomous agent work plus a few hours of human researcher time. This compression of attack timelines represents a fundamental departure from traditional cybersecurity assumptions. Software has historically benefited from “security through complexity,” where exploiting vulnerabilities required extensive expertise, substantial resources, and months of concentrated effort.
The researchers’ work formed part of a broader investigation called “HEIF Heist,” examining how software and services process image file formats. The project discovered vulnerabilities affecting Slack, Zoom, Meta and other platforms across two months using three researchers and less than $3,000 in AI tokens. The cost efficiency and speed of AI-assisted security research contrasts sharply with traditional vulnerability discovery timelines.
Hacktron concluded that AI is fundamentally altering security assumptions by converting specialized expertise into computational capacity. Attackers who previously required elite technical teams and months of preparation can now compress equivalent work into days or hours. The researchers warned that “security assumptions must catch up with attacker capabilities” or organizations face dramatically elevated breach risks.
