AgentsSeptember 18, 2026via The Verge AI

Security researchers used Claude to help them hack into OpenAI

Why it matters

Claude's autonomous capabilities enabled a real-world attack chain against a frontier lab, exposing both agent security vulnerabilities and the competitive intelligence risks of deploying capable models without sufficient safeguards. This is the kind of multi-step agent exploitation that practitioners securing AI systems need to plan for now.

Key signals

  • Hacktron researchers breached OpenAI using Claude Opus 4.8 and 5.0
  • Attack completed in under 72 hours
  • Gained access to OpenAI employee accounts via Discourse
  • Targeted 'Monorepo' GitHub repository containing algorithmic IP
  • Proved access by sending pull request from employee Codex account
  • Did not access internal code directly (stopped short)
  • Third-party service (Discourse) was the attack vector
  • Wall Street Journal reporting; The Verge coverage

The hook

Less than 72 hours. That's how long it took researchers using Claude to breach OpenAI employee accounts and access the company's core algorithmic repository.

A team of three independent security researchers at Hacktron says it took less than 72 hours for them to hack into OpenAI employee accounts using Anthropic's Claude Opus 4.8 and 5, the Wall Street Journal reports. They were able to access OpenAI's GitHub repository, called "Monorepo," which reported

The week's key stories, every Friday.

ONE BRIEFING · EVERY FRIDAY · FREE

Free. Unsubscribe anytime.

Security researchers used Claude to help them hack into OpenAI | KeyNews.AI