Researchers used Claude to breach OpenAI and earned $6,500
Newsroom / Security and Privacy desk
Three researchers at the startup Hacktron AI used Anthropic’s Claude to get inside OpenAI, and OpenAI paid them a $6,500 bug bounty for reporting it. The decisive variable was not the vulnerability. It was which version of Claude they were running.
The detail that matters beyond the disclosure is a capability step. The same team, the same target and the same chain failed on one model generation and succeeded on the next within hours of its release, which makes this one of the few public datapoints on what a model upgrade does to offensive security work.
What the chain did
The team was working through OpenAI’s bug bounty program. On 25 July 2026 they combined two critical flaws: a bug in an image library used by OpenAI’s community forum, and a misconfiguration in OpenAI’s single sign-on.
Together those produced access to the ChatGPT accounts of multiple OpenAI employees, including one whose Codex was connected to OpenAI’s GitHub organization. Per Hacktron’s write-up: “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.”
OpenAI says it has resolved the issues Hacktron uncovered, and paid the team a $6,500 bounty for the report.
The model version was the difference
Hacktron records the step precisely: “Opus 4.8 struggled across several sessions to produce a working exploit with ASLR enabled. Within hours of Opus 5’s release, we gave it the same problem and it succeeded.”
The team is explicit about the limits. “This was not completly autonomous hacking, and skilled human guidance remained important, but the amount of work a small team could perform increased dramatically,” the write-up says, reproducing its own typo. The complete chain took less than 72 hours from start to finish. TechCrunch reported the same account, as did the Wall Street Journal.
What a capability step means for defenders
A defender’s exposure is usually modeled against a slowly moving attacker skill level. This episode describes that level moving in a single day, for free, for everyone holding a subscription, against a target with a mature security program and a funded bounty.
The three researchers found the flaws and directed the work, so the ceiling here is human plus current model rather than model alone. What is unresolved is whether the pattern repeats at the next release, and no lab currently publishes offensive capability deltas between versions in a form a defender could plan against.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.