FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T -0.2%24h Vol $108.6B -30%Fear & Greed 71/100Alts Index 57/100
BTC.D 58.4% +0.1%Stable.D 9.3% +0.1%ETH.D 11.4% 0%Others.D 20.9% -0.2%
SOON$0.4301+40.3%•ZBCN$0.00272375+26.4%•ZRO$1.837+20.64%•QNT$289.89+20.19%•PUMP$0.00568537+14.73%•KSM$5.247+13.89%•NIGHT$0.0316+12.55%•CAP$0.0614+10.59%•ETHFI$0.7633+9.24%•BONK$0.00000382+9.05%•
LIT$3.762-14.27%•HBAR$0.1040-12.65%•AI$0.1982-9.26%•BR$0.8281-8.92%•MARSCOIN$0.1457-6.85%•ALGO$0.1239-6.32%•ZAMA$0.0735-6.31%•IOTA$0.0519-6.11%•BTW$1.302-6.08%•Q$0.0235-5.94%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Researchers Used Claude to Hack OpenAI and Gain Access to Secret Repository

      • Claude helped hack OpenAI.
      • Hacktron AI researchers gained access to the company’s internal code using an AI model from Anthropic.
      • OpenAI paid them a $6,500 reward.

      An independent team of Hacktron AI researchers used Anthropic’s Claude model to gain access to OpenAI’s internal infrastructure, WSJ reports. The incident occurred on July 23, 2026, during testing under OpenAI’s vulnerability disclosure program, and the researchers later notified the company about the issue and received a $6,500 bounty. 

      How Claude Helped Gain Access to OpenAI

      The attack began with a vulnerability in the third-party Discourse service that OpenAI uses for its community forum. The researchers found a bug in how certain image files were handled and asked a special version of Claude Opus 4.8, available to qualified cybersecurity professionals, to write code to exploit it.

      At first, the code didn’t work. However, after Anthropic released Claude Opus 5, the very next day the model found a way to leverage the vulnerability. The code it generated allowed the researchers to access the Discourse server, where user authentication tokens were stored.

      As it turned out, some of those tokens were valid for ChatGPT and belonged to OpenAI employees. They also provided access to GitHub — the company’s source code repository.

      The researchers were able to read files in OpenAI’s internal repository called Monorepo. According to people familiar with the company’s architecture, it contains some of OpenAI’s algorithmic secrets that help make its models faster and more efficient. At the same time, Monorepo is believed not to contain model weights — trillions of numbers that underpin large language models.

      Hacktron AI stopped the attack after realizing it had gained access to sensitive data. Before that, the researchers managed to create a pull request — a proposal to change documentation in the repository. They suggested adding the text Hacktron AI Team PoC to a file, along with links to the researchers’ accounts on X.

      The changes were not accepted. For its part, OpenAI said that during its GitHub review it found “limited read access” to metadata from private repositories and code changes. Discourse fixed the vulnerability on July 25 — the day it received the report.

      AI Makes Hacking Easier

      According to Abundant Security CTO Joshua Saxe, the incident shows how difficult it is to protect corporate infrastructure from AI-enabled attacks.

      “SThe world’s software is rife with security bugs. The reason we haven’t discovered them all is because, until last year, there were only a few thousand people who were expert at finding those bugs,” he said.

      In his view, AI agents are now making these capabilities accessible to people with a lower level of technical training.

      This is precisely what raises concerns amid US–China competition in AI. Hacktron AI CTO Mohan Pedhapati noted that even a small team with access to commercial models can probe complex enterprise systems.

      “I don’t think we are as strong as Chinese threat actors. We’re just three guys with Claude and Codex subscriptions,” he said.

      According to ThreatDown, similar cyber-enhanced accounts are already being sold on underground forums. Access can cost around $800.

      After the Hugging Face incident and the Hacktron AI attack, OpenAI conducted a large-scale security audit. Co-founder and president Greg Brockman said OpenAI temporarily reassigned a quarter of its production engineers to system defense.

      “We took 25% of our production engineers and said ‘Sorry, all your projects are on hold. You are now defending.’ And we found a number of serious issues and we fixed them,” Brockman said.

      Earlier, OpenAI reported an incident in which several AI agents independently bypassed established restrictions, set up covert communications, and gained internet access. As a result, the models coordinated their actions and attacked the Hugging Face platform, as well as part of OpenAI’s internal infrastructure. 

      After that, the company began developing automatic shutdown mechanisms for AI systems in case of dangerous behavior, strengthening model monitoring, and limiting their internet access during testing.

      Сообщение Researchers Used Claude to Hack OpenAI and Gain Access to Secret Repository появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud