Researchers hacked OpenAI in under 72 hours using Claude
A three-person Hacktron team accessed OpenAI's GitHub Monorepo via a Discourse forum exploit.
Three researchers at Hacktron breached OpenAI employee accounts in less than 72 hours, using Anthropic's Claude Opus 4.8 and 5, The Wall Street Journal reports via The Verge. The attack vector was Discourse, the third-party forum software hosting OpenAI's community platform, exploited alongside a corrupted image file.
The team reached OpenAI's internal GitHub repository, Monorepo, described by sources as containing OpenAI's algorithmic secrets. They stopped short of pulling internal code directly. Instead they sent a pull request from an employee's Codex account to demonstrate confirmed access. The same team also hacked Meta and Slack.
The attack was not a zero-day against OpenAI's core infrastructure. It ran through a third-party vendor. That is the detail to watch. Perimeter security is only as strong as the weakest hosted service in the stack. OpenAI's exposure came from forum software, not its model layer.
Analysis
Capability used as offense: Claude helped breach the lab that competes with its maker. Third-party vendors, not frontier models, remain the reliable attack surface.
Research this with your AI
Copy the research prompt into your AI assistant to see how this story affects you.
Show the prompt
I just read this AI news story and want to understand it in my own context. Title: Researchers hacked OpenAI in under 72 hours using Claude Summary: Three independent researchers at Hacktron used Claude Opus 4.8 and 5 to breach OpenAI employee accounts in under 72 hours. They reached OpenAI's Monorepo repository, which reportedly holds algorithmic secrets, via a Discourse forum vulnerability. Category: Industry Source: The Verge, https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist Using my own history and context, help me understand: 1. What is the core development and why does it matter? 2. Who are the major players involved and what are their motivations? 3. How does this fit into the broader AI landscape right now? 4. How does this apply to my own work, and what should I do or watch next? Be specific and plain spoken.
Newsletter
The day's AI stories, with the editor's take, in one email.
Free. Unsubscribe in one click.