Researchers used Claude to hack OpenAI
Researchers exploited a Discourse misconfiguration on OpenAI's community forum to reach internal sign-ons and an employee ChatGPT account with GitHub code access; OpenAI fixed it.
Researchers, first reported by the Wall Street Journal, exploited a flaw in the third-party Discourse-hosted setup of OpenAI's community forum to gain access to internal sign-ons and eventually an OpenAI employee's ChatGPT account, which had access to internal code through GitHub. OpenAI thanked the researchers and said it had fixed the issues; Anthropic declined to comment and Hacktron did not immediately respond. The disclosure, which did not detail how Claude was used in the operation, coincided with Anthropic publishing data showing 26% of its R&D work was led by Claude, up from 1% in March.
- Flaw in Discourse-hosted OpenAI community forum exposed internal sign-on access
- Compromise reached an employee ChatGPT account with GitHub access to internal code
- OpenAI confirmed the issues are fixed and thanked researchers; Anthropic declined comment
- Anthropic says 26% of R&D work is led by Claude, up from 1% in March
Full article278 words · extracted from arstechnica.com · click to collapse
They exploited a flaw in the set-up of OpenAI’s community forum, which is hosted by a third-party, Discourse, and used it to gain access to internal sign-ons and eventually an OpenAI employee’s ChatGPT account. This ChatGPT account had access to internal code through GitHub.
“We thank the researchers for contacting us and sharing their findings,” OpenAI said, adding that it had fixed the issues. Anthropic declined to comment. Hacktron did not immediately respond.
The disclosure on Thursday, first reported by The Wall Street Journal, came as Anthropic published a new set of data that showed a rapid increase in how much the lab used AI to develop its new models.
It said 26 percent of research and development work was “led by” its Claude model, up from 1 percent in March, meaning that AI completed the majority of tasks based on human instruction and under supervision.
The company said that as AI systems become more powerful, they were “increasingly being used to build the next version of themselves.”
Anthropic said it shared the data to help the public “understand how close the world is to reaching recursive self-improvement,” the point at which AI can train and improve itself or new models.
This threshold is at the heart of concerns that AI systems will become more difficult to oversee, leading to a loss of human control.
Its models did not yet operate fully autonomously for any of the research it studied, Anthropic added. On 90 percent of tasks, AI “collaborates” with a human and does large chunks of work.
© 2026 The Financial Times Ltd. All rights reserved. Not to be redistributed, copied, or modified in any way.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/