Techsoma Africa
Latest FinTech Startups AI Tech Global Apps African Opinions
Policy & Regulations Artificial Intelligence Reports About Contact Advertise FinTech & Digital Money African Startup Ecosystem Artificial Intelligence Technology Global News Apps, Gadgets, Tools & Softwares African Telecommunications Opinions & Perspectives
Advertisement Advertise on Techsoma
Techsoma Africa
No Result
View All Result
Techsoma Africa
No Result
View All Result
Techsoma Africa
No Result
View All Result
Home Cybersecurity

How a 3-Person Team Used Claude to Hack OpenAI in 72 Hours

by Onyinye Moyosore
September 21, 2026
in Cybersecurity, Global News
Reading Time: 3 mins read
Code on a laptop screen, illustrating Hacktron AI security research that reached OpenAI's internal systems

A small security startup has shown how far AI-assisted hacking has come, using one AI company’s model to break into another.

Researchers at Hacktron AI used Anthropic’s Claude to gain access to the ChatGPT and Codex accounts of several OpenAI employees, and from there reached OpenAI’s internal code repository on GitHub. The team, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, disclosed the work this week after first reporting it to OpenAI in July. The Wall Street Journal reported it on 18 September.

How They Got In

The attack chained two separate weaknesses.

The first was a memory flaw in image-processing software used by Discourse, the platform running OpenAI’s public community forum. Exploiting it let the team run code on OpenAI’s forum server.

Advertisement Advertise on Techsoma

The second was in OpenAI’s own login system. According to Hacktron, the token-reuse problem sat in OpenAI’s identity infrastructure, not in Discourse, which meant the forum was only an entry point. Any other OpenAI service connected to the same single sign-on could have played that role.

Combined, the two flaws let the team take over the accounts of active forum members who were OpenAI staff, without those employees doing anything. The full path took less than 72 hours.

What They Did, and Didn’t Do

One compromised employee’s Codex account was connected to OpenAI’s GitHub organisation. To prove the level of access without reading anything sensitive, the researchers prompted that Codex account to open a pull request in OpenAI’s internal repository, named openai/openai.

That was the only action taken. Hacktron says it did not read source code, merge or ship anything, or touch customer data. What the chain could theoretically have reached was far larger, since employees connect ChatGPT and Codex to other tools, potentially including GitHub, Slack and email. That wider access existed but wasn’t used.

How Claude Was Involved

The researchers first tried Claude Opus 4.8, which struggled across several sessions to produce a working exploit. When Anthropic released Opus 5, they tried again and succeeded. They used a special version of Claude that Anthropic makes available to qualified cybersecurity practitioners.

Claude also refused at one point. According to Hacktron’s own write-up, the model declined to write an exploit for a remote target. The team got around this by pointing it at their own copy of the forum software, set up to look like a capture-the-flag practice target, and then used the resulting exploit against OpenAI’s live forum.

OpenAI’s Response

OpenAI fixed the issue about 14 hours after the report and paid the team a $6,500 bounty through its Bugcrowd programme on 1 September. The company said the award covered the flaw on OpenAI’s side, not the actions against Discourse, since testing the forum software itself fell outside the bounty’s scope.

Why It Matters

The researchers’ own summary is the headline. Work that once required a well-resourced team and months of effort can now be compressed into days, they told The Guardian, and each new model is more capable than the last.

Related Techsoma coverage

  • WhatsApp Opens to Third-Party AI Agents After EU Ruling
  • EFCC Warns PoS Agents Against Money Laundering and Terror Financing
  • Zenith Bank Confirms Data Breach Exposing Customer Emails and Phone Numbers
Onyinye Moyosore

Onyinye Moyosore

Onyinye Moyosore is a tech writer at Techsoma, where she covers startups, digital infrastructure, and how technology reshapes everyday life...

Recommended For You

Whatsapp
Artificial Intelligence

WhatsApp Opens to Third-Party AI Agents After EU Ruling

by Faith Amonimo
September 21, 2026

Meta built a wall around WhatsApp and kept every rival AI assistant outside. The European Commission knocked that wall down. In October 2025, Meta announced it would ban all third-party...

Read moreDetails
EFCC speaks to POS agents

EFCC Warns PoS Agents Against Money Laundering and Terror Financing

September 18, 2026
A Zenith bank building

Zenith Bank Confirms Data Breach Exposing Customer Emails and Phone Numbers

August 6, 2026

Terra Industries Partners With Miva University To Build Robotics And Drone Labs Across Nigeria

July 31, 2026

Facebook launches Marketplace Seller App and free verification

July 29, 2026
Please login to join discussion

Browse by Category

  • African Startup Ecosystem
  • African Telecommunications
  • Apps, Gadgets, Tools & Softwares
  • Artificial Intelligence
  • Business & Markets
  • Consumer Tech
  • Creator Economy
  • Cybersecurity
  • Digital Work-Life Series
  • E-Commerce
  • Education
  • Event Radar Africa
  • Exclusive Interviews
  • Explainers
  • Features/Spotlights
  • FinTech & Digital Money
  • Funding news
  • GenZ Desk!
  • Global News
  • Healthtech
  • Logistics & Mobility Tech
  • Media & Entertainment
  • News
  • Opinions & Perspectives
  • Opportunities, Careers & Learning
  • Partner
  • Policy & Regulations
  • Reports
  • Reviews
  • Tech Insights for Creators
  • Technology
  • Thought Leadership
  • Uncategorized
  • About Us
  • Advertise on Techsoma
  • Contact
  • Corrections Policy
  • Editorial Standards
  • Ownership and Funding
  • Privacy Policy
  • Publish Your Articles
  • Techsoma Africa
  • Terms of Service

Copyright 2026 Techsoma Africa. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Advertisement Advertise on Techsoma
Techsoma Africa

© 2026 Techsoma Africa Media.

Company

Policy AI Reports About Contact Advertise

Legal

Terms Privacy RSS

Latest

How a 3-Person Team Used Claude to Hack OpenAI in 72 Hours Three researchers at Hacktron AI used Anthropic's Claude to chain two flaws, take over the ChatGPT and Codex accounts of several OpenAI employees, and reach the company's internal code repository in under 72 hours. It was authorised research: they proved access with a harmless pull request, reported it, and OpenAI paid a $6,500 bounty after fixing it in about 14 hours. Nigeria Records First Tele-Robotic Surgery as Ogun Surgeon Removes Kidney Tumour in Abuja A surgeon in Ogun State has removed a cancerous kidney from a patient in Abuja, about 500 kilometres... African Tech Startups Pull in About $2bn in 2026 as Mega-Deals Take Over African tech startups have raised about $2 billion in the first eight months of 2026. The headline figure...
Techsoma Network Techsoma Network Techsoma Africa Techsoma Middle East Techsoma Canada
Transparency About Editorial Standards Corrections Ownership & Funding Privacy Terms Contact
No Result
View All Result
  • About Us
  • Advertise on Techsoma
  • Contact
  • Corrections Policy
  • Editorial Standards
  • Ownership and Funding
  • Privacy Policy
  • Publish Your Articles
  • Techsoma Africa
  • Terms of Service

Copyright 2026 Techsoma Africa. All rights reserved.