Researchers used Claude to hack OpenAI
Security researchers used Anthropic’s Claude model to exploit a misconfiguration in OpenAI’s community forum hosted on Discourse, gaining access to internal sign-ons and an OpenAI employee’s ChatGPT account that could reach GitHub code. OpenAI said the issues have been fixed and thanked the researchers; Anthropic declined to comment.

Why It Matters
The incident illustrates how advanced AI tools can be used to chain together weaknesses in third‑party systems to reach sensitive corporate resources, reinforcing concerns about oversight and the security implications of AI-assisted workflows. It also comes as Anthropic disclosed growing use of its own models to drive research and development.
Key Facts
- Exploit method: Researchers used Anthropic's Claude to exploit a flaw in OpenAI’s Discourse-hosted forum setup.
- Access gained: Internal sign-ons and an OpenAI employee’s ChatGPT account were accessed; that account had access to internal GitHub code.
- Response from OpenAI: OpenAI thanked the researchers for sharing findings and said it had fixed the issues.
- Anthropic response: Anthropic declined to comment.
- Reporting: The disclosure was first reported by The Wall Street Journal on Thursday.
Security researchers demonstrated a chain of weaknesses that used Anthropic’s Claude model to penetrate parts of OpenAI’s internal systems. The researchers exploited a misconfiguration in OpenAI’s community forum, which is hosted by the third-party discussion platform Discourse, and used that access to reach internal sign-on mechanisms and ultimately an OpenAI employee’s ChatGPT account. That ChatGPT account had access to internal code stored on GitHub.
OpenAI said it had been contacted by the researchers, thanked them for sharing their findings, and fixed the identified issues. Anthropic declined to comment on the matter. A separate group named Hacktron did not immediately respond to requests for comment. The initial public report of the disclosure was published by The Wall Street Journal.
The disclosure coincides with Anthropic’s release of internal data showing a sharp rise in how much its Claude model is used in research and development. Anthropic reported that 26 percent of R&D work was “led by” Claude, up from 1 percent in March; the company described this as meaning the model completed the majority of tasks based on human instruction and supervision. Anthropic framed the release as a way to inform the public about how close AI may be to achieving so-called recursive self-improvement, where systems train and improve themselves or new models.
Anthropic also noted that, in the research it examined, its models were not yet operating fully autonomously: on roughly 90 percent of tasks the AI “collaborates” with a human and performs substantial portions of the work. The episode and the accompanying data highlight tensions between accelerating AI-driven workflows and the security and governance challenges of increasingly capable models and complex third‑party software stacks.
Keep Reading

US government website used Chinese model the FBI called "malicious"

FAA tees up $875M AI tool to help manage air traffic congestion

AI hallucination of Chinese nuclear components almost led to US military attack

Manus seeks $4B valuation in new $500M fundraise as it resumes independent ops
Original source: Ars Technica AI
Also reported by TechCrunch.