Researchers used Claude to breach OpenAI and earned $6,500
Three researchers at the startup Hacktron AI used Anthropic's Claude to compromise OpenAI accounts through OpenAI's own bug bounty program, and were paid $6,500. On 25 July 2026 they chained two critical flaws, a bug in an image library used by OpenAI's community forum and a misconfiguration in OpenAI's single sign-on, obtaining the ChatGPT accounts of multiple OpenAI employees, including one whose Codex was connected to OpenAI's GitHub organization. They opened a single pull request in OpenAI's internal repository and stopped. Claude Opus 4.8 failed to produce a working exploit across several sessions; Opus 5 solved the same problem within hours of release. The full chain took under 72 hours, and the team says human guidance remained important throughout.