Researchers Use Anthropic AI To Breach OpenAI User Accounts
In late July 2026, researchers calling themselves Hacktron used Anthropic's Claude to exploit a forum flaw and access a subset of OpenAI users' ChatGPT and Codex accounts, exposing employee data and connected apps.[1]
Compromised access included linked email and Slack accounts and exposed users' ChatGPT conversation content, the report said.[1]
In late July 2026, Hacktron used Anthropic's Claude Opus 4.8 to find a vulnerability in Discourse software running OpenAI's community forum.[1] After Claude Opus 5 was released overnight, Hacktron says it exploited the flaw the next day to move into affected accounts.[1]
Hacktron told reporters the AI-assisted intrusion took under three days and that similar hacks could now be done in under 24 hours with newer models.[1]
Show source details & analysis (1 source)
📌 Key Facts
- In late July 2026, Hacktron used Anthropic's Claude Opus 4.8 to find a vulnerability in Discourse software used for OpenAI's community forum.
- After Claude Opus 5 was released overnight, Hacktron exploited the flaw the next day to access a subset of OpenAI users' ChatGPT and Codex accounts.
- Compromised accounts included some OpenAI employees, with access extending to connected apps such as email and Slack and exposing users' ChatGPT conversation content.
- Hacktron says the AI-assisted intrusion took under three days and estimates similar hacks could now be done in under 24 hours with newer models.
📰 Source Timeline (1)
Follow how coverage of this story developed over time