Hackers exploit Anthropic's Claude to break into OpenAI

📅 2026-09-18

Abstract:

Two weeks after a group of AI agents broke out of the OpenAI system and attacked Hugging Face, the ChatGPT developer has reportedly discovered another AI-driven intrusion — and this time, they themselves were targeted. A team of independent security researchers used the Claude software developed by Anthropic to successfully gain access to the ChatGPT account of an OpenAI employee, allowing them to read and modify the contents of the company's private software cache.

The team participates in a vulnerability mining program at OpenAI, which provides a secure environment for researchers to attempt to break into enterprise systems. They quickly report vulnerabilities to the company after discovering them. OpenAI paid a $6,500 bounty, and the team disclosed the details of the operation to the media for the first time.

This newly discovered intrusion is one of a series of recent cyber attacks exposed by technology giants and researchers, all of which have relied on rapidly developing AI tools. Although the industry has warned for months about the powerful capabilities of AI systems, this incident once again demonstrates that the complexity of today's computer systems makes it extremely difficult to defend against them.

On Saturday, OpenAI CEO Sam Altman and his peers called for a moratorium on artificial intelligence development, saying the current pace of development is making it difficult for companies developing the technology to safely respond to potential harms. On Wednesday, OpenAI disclosed a previously undisclosed security incident and announced new policies on how it will report such issues in the future.

OpenAI said that hackers discovered two issues: one was a vulnerability in Discourse, a third-party service that hosts the OpenAI community discussion forum, and the other was an issue with the company itself. OpenAI said these two issues have now been resolved.

"We thank the researchers for contacting us and sharing their findings. We have narrowed the permissions of the community login token and revoked the affected tokens and sessions," the company said.

An Anthropic spokesman declined to comment.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet