← Founder Notes
Archive

White-hat researchers used anthropic's claude to get into an openai employee's chatgpt account and…

Yethikrishna ROriginal on Threads

white-hat researchers used anthropic's claude to get into an openai employee's chatgpt account and read openai's private code caches — openai paid them $6,500. the tools you ship can be used against you by the same agent vendors' models.

security teams are now on both sides of the same agent.

Context

Secondary coverage dated 18 and 22 September 2026 says a small team, Hacktron AI, chained two vulnerabilities, an RCE through image processing on OpenAI's Discourse forum and an SSO weakness, with help from Claude Opus 5, and reported it through Bugcrowd on 25 July 2026. Hacktron's timeline says the chain reached multiple employee ChatGPT accounts and internal repositories in under 72 hours. The coverage says OpenAI fixed its side about 14 hours after the report and paid 6,500 dollars, and that the award covered its identity flaw, not testing of the out-of-scope Discourse forum.

How it compares

All of this rests on secondary coverage; Hacktron's own writeup and OpenAI's statement were not inspected. The coverage says the episode did not establish that Claude autonomously breached OpenAI or that the researchers copied private source code, so read private code caches and Claude got into the account are broader than the sources. The writeup's claim is that access was proven through a connected Codex account. The 6,500 dollar figure is secondary.

Related work

Watch next

  • Hacktron's own report and OpenAI's bounty statement.

Sources

  1. A Claude-assisted image exploit reached OpenAI repositories in under 72 hours (Quasa, 22 Sep 2026)quasa.io

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 07:21 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/white-hat-researchers-used-anthropic-s-claude-to-DdaS8e1COuP" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="White-hat researchers used anthropic's claude to get into an openai employee's chatgpt account and…"></iframe>

More notes