thread.news
← Back
AHighly CredibleTech🇺🇸US⚠ Coverage gap9/18/2026, 4:00:43 PM
Security Researchers Use Claude AI to Access OpenAI Internal Systems

Security Researchers Use Claude AI to Access OpenAI Internal Systems

A team of independent researchers successfully accessed OpenAI employee accounts and a sensitive GitHub repository by utilizing Anthropic's Claude AI. The researchers demonstrated the breach by submitting a pull request to prove they had gained unauthorized entry.

Share
Coverage
leftcenterrightinternationalinvestigative

A team of three independent security researchers from the group Hacktron recently demonstrated a vulnerability in OpenAI’s internal systems by using Anthropic’s Claude AI models. According to reports, the researchers gained access to OpenAI employee accounts and a sensitive GitHub repository known as "Monorepo" in under 72 hours. The repository reportedly contains proprietary algorithmic information belonging to OpenAI.

While the researchers successfully breached the systems, they did not download or access the internal code stored within the Monorepo. Instead, to verify the extent of their access, they submitted a pull request using an employee’s compromised Codex account. The breach was reportedly facilitated through vulnerabilities in Discourse, a third-party platform used by the company.

Sources differ slightly on the scope of the reporting. Ars Technica provides a concise overview focusing on the use of Claude as the primary tool for the exploit. The Verge provides more granular detail, citing the Wall Street Journal, and specifies that the researchers were independent and that the exploit took less than three days to execute. Both outlets agree that the incident highlights potential security risks associated with the integration of AI tools in cybersecurity research and the vulnerabilities of third-party platforms connected to sensitive corporate data.

📡 Media Analysis

How each outlet framed the story — angles, word choices, and what they chose to push or ignore.

Ars TechnicaCenterA+

Provided a brief, high-level summary of the event without unnecessary narrative flair.

"Researchers used Claude to reach an OpenAI employee account"

"used Claude to hack"
The VergeCenterA

Focused on the timeline and the specific nature of the data accessed, relying on secondary reporting.

"it took less than 72 hours for them to hack into OpenAI"

"help them hack"

✓ Only outlet to report: Identified the specific name of the repository ('Monorepo') and the third-party platform ('Discourse') involved.

Where Sources Disagree

  • ·The extent to which Claude was the primary driver of the hack versus a supporting tool for the researchers.

🔍 What Nobody's Reporting

  • ·OpenAI's official response or confirmation regarding the security breach.
  • ·Details on how Anthropic views the use of its AI models for offensive cybersecurity operations.

📰 Sources

1 A-rated source(s) among 2 total. Lowest trust: The Verge (B)