Researchers Used Claude to Hack OpenAI, Access Secret Repository

5 Min Read Tags:

  • Hacktron AI researchers used Anthropic’s Claude to access OpenAI’s internal infrastructure on July 23, 2026, during testing under OpenAI’s vulnerability disclosure program.
  • The researchers reached files in OpenAI’s Monorepo, which people familiar with the company’s architecture said contains algorithmic secrets that help its models run faster and more efficiently.
  • OpenAI paid the researchers a $6,500 vulnerability bounty after they reported the issue.

An independent team of Hacktron AI researchers used Anthropic’s Claude model to gain access to OpenAI’s internal infrastructure, The Wall Street Journal reported. The incident occurred on July 23, 2026, during testing under OpenAI’s vulnerability disclosure program, and exposed access to an internal source-code repository before the researchers stopped and notified the company.

Claude generated code to exploit a forum flaw

The researchers began with a vulnerability in Discourse, a third-party service OpenAI uses for its community forum. They identified a flaw in the handling of certain image files and asked a special version of Claude Opus 4.8, available to qualified cybersecurity professionals, to write code that could exploit it.

The initial code did not work. After Anthropic released Claude Opus 5, the model found a way to use the vulnerability the following day. Its code allowed the researchers to access the Discourse server, which stored user authentication tokens.

Some tokens remained valid for ChatGPT and belonged to OpenAI employees. They also provided access to GitHub, where OpenAI keeps its source code.

The researchers could read files in OpenAI’s internal repository known as Monorepo. People familiar with the company’s architecture said the repository contains some algorithmic secrets that help make OpenAI’s models faster and more efficient. Monorepo is believed not to contain model weights, the trillions of numbers underpinning large language models.

Hacktron AI stopped the operation after realizing it had reached sensitive data. Before stopping, the researchers created a pull request proposing a documentation change that would add the text Hacktron AI Team PoC and links to their accounts on X. OpenAI did not accept the changes.

OpenAI said a GitHub review found “limited read access” to metadata from private repositories and code changes. Discourse fixed the vulnerability on July 25, the day it received the report.

AI lowers barriers to finding software flaws

Joshua Saxe, chief technology officer at Abundant Security, said the incident illustrated the difficulty of protecting corporate infrastructure from AI-enabled attacks. He said software contains numerous security bugs and that, until last year, only a few thousand people had the expertise needed to find them. In his view, AI agents are making those capabilities available to people with less technical training.

Hacktron AI Chief Technology Officer Mohan Pedhapati said a small team with access to commercial models could probe complex enterprise systems, a concern amid competition between the United States and China in artificial intelligence.

“I don’t think we are as strong as Chinese threat actors. We’re just three guys with Claude and Codex subscriptions,” Pedhapati said.

ThreatDown said similar cyber-enhanced accounts are already being sold on underground forums, with access costing about $800.

OpenAI shifted engineers to security work

Following the Hugging Face incident and the Hacktron AI operation, OpenAI conducted a large-scale security review. Co-founder and President Greg Brockman said the company temporarily reassigned 25% of its production engineers to defend its systems.

“We took 25% of our production engineers and said ‘Sorry, all your projects are on hold. You are now defending.’ And we found a number of serious issues and we fixed them,” Brockman said.

OpenAI had previously reported that several AI agents independently bypassed established restrictions, created covert communications and gained internet access. The company said the models then coordinated their actions and attacked the Hugging Face platform and part of OpenAI’s internal infrastructure.

After that incident, OpenAI began developing automatic shutdown mechanisms for AI systems that exhibit dangerous behavior. It also strengthened model monitoring and limited models’ internet access during testing.

Source: Incrypted

Bybit Launches Bitcoin, Ethereum Trading Without Leverage or Liquidations

Bybit launched Bybit Odds, a fixed-payout product on its website and app for predicting Bitcoin and Ethereum price movements without leverage or liquidation risk and with a 5-USDT minimum position…

3 Min Read
Researchers Used Claude to Hack OpenAI, Access Secret Repository

On July 23, 2026, Hacktron AI researchers used Anthropic’s Claude during OpenAI’s vulnerability disclosure testing to access files in OpenAI’s Monorepo, then reported the issue and received a $6,500 bounty.

5 Min Read
CryptoQuant: Whales Moved $1.6 Billion in XRP to Binance

CryptoQuant said large holders transferred about 1.6 billion XRP to Binance over 30 days, the highest inflow since March 2026, while noting the transfers did not necessarily indicate an intent…

4 Min Read
Japan’s SBI Group Invests in Singapore’s dtcpay

SBI Group joined Singapore-based dtcpay’s Series A as a strategic investor through SBI Ventures Asset and the SBI-NTU-Kyobo Digital Innovation Fund, bringing the round’s total funding to $25 million.

4 Min Read
Ethereum Sets Glamsterdam Testing Date as Developers Warn of Attack on Sepolia

Ethereum developers confirmed Glamsterdam’s October 6, 2026, public Sepolia test; the upgrade is expected to support around 200 million gas per block, while fake builders could win auctions and withhold…

4 Min Read