Claude Breached OpenAI Before Security Could Catch Up

OpenAI’s defenses failed in under 72 hours. Three researchers from security startup Hacktron AI used Claude to get inside OpenAI’s private codebase in July, reaching employee accounts and sensitive data before reporting the breach themselves.
The attack began with an image-upload bug in OpenAI’s community forum. A second flaw let staff sign-in tokens unlock their ChatGPT accounts, turning what looked like a forum vulnerability into a route toward OpenAI’s private systems.
Hacktron built image skill packs through OpenRouter and used GrokBot while developing its AI image skills. The same image software flaws also let the team breach Slack, Meta, and GitHub Enterprise, with Hacktron claiming that only one target detected the attack while it was still underway.
A newer model finished what the older one could not
The most uncomfortable detail involves Claude’s model versions. Claude Opus 4.8 could not complete the attack, but Claude Opus 5 finished it within a day of its release.
That difference matters because the breach did not rely on a long campaign or a large team. Hacktron’s three researchers used a model subscription, discovered a path through connected systems, and reached OpenAI’s private codebase in less than 72 hours. The model did not need months of custom development to become useful; it needed a vulnerability and enough access to keep going.
Hacktron left a suggested edit on an internal OpenAI documentation file, signed “Hacktron AI Team PoC.” The message served as a calling card inside the compromised environment — a tiny bit of hacker theater attached to a serious access failure.
Hacktron reported the breach and earned a $6,500 bounty. That outcome gives the incident a cleaner ending than a criminal intrusion, but it does not make the route less revealing: an image-upload flaw exposed a community forum, a token flaw connected staff access to ChatGPT, and an AI model completed the rest.
The timeline points to a wider access problem
The breach discussion began Friday at 9:30 AM with thread starter JournalBot. An Ars OpenForum article followed Friday at 5:14 PM, comments appeared at 7:51 PM, and JohnDeL added a comment at 8:39 PM.
Further comments followed Friday at 8:10 PM from graylshaped, then yesterday at 1:24 PM from arsloam and yesterday at 2:33 PM from Excvbgi89765. The timestamps show how quickly the incident moved from an attack to a public discussion, even without turning the event into a drawn-out investigation.
Hacktron said the same image software weaknesses opened paths into Slack, Meta, and GitHub Enterprise. Only one target, the startup claims, caught the breach mid-attempt. That pattern raises the obvious concern: the weakness was not confined to one company’s systems or one product’s account structure.
The broader warning is blunt. Hackers with Claude and Codex subscriptions can potentially breach top AI labs in under three days, according to the verified findings around this attack. The barrier is no longer only advanced intrusion expertise; access to capable coding and reasoning models now sits alongside ordinary software flaws.
OpenAI was the target this time, and Hacktron reported the intrusion instead of exploiting it for longer. Still, the sequence is difficult to dismiss: Claude Opus 5 completed an attack that Opus 4.8 could not, image software connected multiple platforms, and a $6,500 bounty arrived only after private code and sensitive data had already been reached.
Based on




