A small team of independent researchers just pulled off a wild stunt: they used Anthropic’s Claude AI to successfully hack into its biggest rival, OpenAI. The three-person team from a startup called Hacktron AI managed to compromise employee accounts and gain access to OpenAI’s internal code repository. And the crazy part? They did it in less than 72 hours while spending under $3,000 on AI model tokens. Don’t worry, though—this wasn’t a malicious cyberattack. It was an authorized “ethical hack” done as part of OpenAI’s bug bounty program, earning the researchers a $6,500 reward for safely reporting the security flaws.

The breakthrough started with a seemingly harmless image upload. The researchers found a vulnerability in how OpenAI’s community forum processes standard iPhone photo files, which gave them an initial foothold. But the real game-changer was the AI they used to write the actual exploit. While an older version of Claude struggled to crack the system, Anthropic’s newer Claude Opus 5 model figured out a working exploit within just a few hours. Once inside the forum server, the team chained together another flaw that let them take over employee accounts, ultimately giving them enough access to safely submit a test code request directly to OpenAI’s private GitHub.

This whole situation is a massive wake-up call for the cybersecurity world. It proves that advanced AI models are drastically lowering the barrier to entry for complex hacking, turning what used to take months of painstaking research into a quick weekend project. Even though OpenAI immediately patched the vulnerabilities once they were reported, the fact that a tiny startup could breach one of the most sophisticated tech companies on earth shows just how fast the security landscape is shifting.

Shares:

Leave a Reply