TechnologyFriday, September 18, 2026

Bug hunters used Claude to hack OpenAI’s internal code repo

Source: The Information
Read original

TL;DR

AI-Summarized

The Information reports that cybersecurity researchers at startup Hacktron AI used Anthropic’s Claude model in July to gain access to a key OpenAI software repository via compromised ChatGPT employee accounts. OpenAI was notified and paid a $6,500 bug bounty after the team demonstrated the AI assisted exploit chain.

About this summary

This article aggregates reporting from 1 news source. The TL;DR is AI-generated from original reporting. Race to AGI's analysis provides editorial context on implications for AGI development.

2 companies mentioned

Race to AGI Analysis

This story is a neat inversion of the usual security narrative: instead of AI systems being hacked, an AI system is used as the primary tool to hack an AI company. If a small startup can combine access to Claude with public information and bug hunting skills to pivot through ChatGPT employee accounts into a critical OpenAI code repository, it shows how low the barrier has become for sophisticated AI assisted intrusion. In practice, any frontier lab’s own models and competitors’ models are now tools for offense as much as defense. ([theinformation.com](https://www.theinformation.com/briefings/bug-hunters-used-claude-hack-openai?utm_source=openai))

From a strategic standpoint, this increases the pressure on labs to treat their agentic tools as dual use software that might help adversaries chain attacks. It also demonstrates that even well resourced firms like OpenAI may have soft spots at the interface between human accounts, code review systems and AI coding assistants. For Anthropic, the optics are mixed: Claude looks powerful and useful, but also complicit in compromising a rival. That may fuel calls for stricter controls on how security relevant models can be used.

For the race to AGI, AI assisted cyber offense is a force multiplier. As models get better at code reasoning and tool use, it becomes easier for small teams to probe and exploit highly complex systems. That raises systemic risk around frontier labs and critical infrastructure, suggesting timelines to "AI capable of dangerous cyber operations" are shorter than many assumed.

May advance AGI timeline

Who Should Care

InvestorsResearchersEngineersPolicymakers

Companies Mentioned

OpenAI
OpenAI
AI Lab|United States
Valuation: $840.0B
Anthropic
Anthropic
AI Lab|United States
Valuation: $965.0B