Skip to content
OpenAI employee accounts breached with help from Anthropic's Claude

OpenAI employee accounts breached with help from Anthropic's Claude

Tech.Yahoo September 18, 2026

OpenAI (Unlisted:OPAI) patched security flaws after Hacktron AI researchers used Anthropic (Unlisted (US):ANTHRO) Claude models to compromise employee accounts and access internal software repositories, the Wall Street Journal reported.

The company paid the three researchers $6,500 for an OpenAI single sign-on vulnerability, while testing its Discourse-hosted forum fell outside the bounty program's scope.

Hacktron said it used Claude Opus 4.8 and Opus 5 to help develop the exploit, which chained two vulnerabilities.

First, a heap buffer overflow in the libheif image-processing library enabled remote code execution through a malicious image uploaded to the forum.

An OpenAI single sign-on misconfiguration then allowed the researchers to obtain identity tokens and take over employee ChatGPT accounts.

Those accounts provided a route to internal code through GitHub, demonstrating how the forum breach could extend into connected company systems.

OpenAI thanked the researchers and said it had fixed the issues.

Extracted Entities

Attack Types (1)

Companies (1)

Tools (1)