Researchers used Anthropic’s Claude to hack into OpenAI
- ID
- 25922
- Status
- summarized
- Published
- 18 Sep 2026, 10:00 PM
- Fetched
- 18 Sep 2026, 10:09 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/18/researchers-used-anthropics-claude-to-hack-into-openai/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 7.5
- Created
- 18 Sep 2026, 10:10 PM
- Tags
- Audience
- developersai_ml_learnersai_agent_userssaas_founders
What happened
A three-person team at startup Hacktron AI used Anthropic's Claude (Opus 5) to chain two critical vulnerabilities and access multiple OpenAI employee ChatGPT accounts, earning a $6,500 bug bounty. The entry point was a mundane HEIF/HEIC image upload flaw in Discourse, the third-party software powering OpenAI's community forum, discovered on July 25. OpenAI says the issues are resolved.
Why it matters
For ~$200/month of off-the-shelf AI tooling, a small team penetrated one of the most security-conscious AI companies via a third-party forum component and a default iPhone image format. If you run any community forum (Discourse is widely used) or accept user image uploads, treat HEIF/HEIC handling and forum plugin surfaces as real attack vectors now, not theoretical ones. This also signals that AI-assisted vulnerability chaining is cheap enough to be routine.
Discussion angle
The attack wasn't a novel model exploit — it was cheap AI-assisted chaining of mundane third-party software flaws. What does that mean for how small teams should prioritize patching forum plugins and image-upload pipelines versus building bespoke AI security tooling?