A security research company reported on Friday that it managed to gain access to OpenAI's internal systems using the latest software from Anthropic. This incident demonstrated how quickly technologies can conduct complex cyberattacks.
Researchers from the security firm Hacktron discovered a vulnerability in OpenAI's public help forum, which runs on the Discourse platform. This vulnerability allowed them to take control of the site.
In its blog, Hacktron stated: 'We immediately reported the initial vulnerability to OpenAI and Discourse and worked with them to coordinate a fix.' The same post added: 'We appreciate their attention to detail and quick resolution of this issue.'
OpenAI confirmed that the vulnerability was patched approximately 14 hours after receiving notification and paid the researchers a reward of $6,500. An OpenAI representative, Drew Pusateri, stated: 'We thank the researchers for reaching out to us and providing their findings. We have narrowed the permissions for community login tokens and revoked the affected tokens and sessions.'
Hacktron researchers explained that they initially used Anthropic's Claude Opus 4.8 to discover and exploit the software vulnerability but encountered difficulties ensuring stable operation. After Anthropic released the Claude Opus 5 model, the researchers noted that the newer version allowed the breach to be executed within approximately three hours.
The hackers did not use Claude Mythos—a more powerful model from Anthropic whose access is restricted to a small group of vetted cybersecurity organizations. Anthropic describes Mythos as its most capable model in the field of cybersecurity among all it has created.
Hacktron emphasized that the underlying software vulnerability is not unique to OpenAI and is used in many products from various companies, including Slack and Meta products. The firm continues similar tests at other companies.
This case reinforces growing concern among security experts that AI tools are making complex cyberattacks faster and cheaper than before, when they required specialized teams and months of work.
