Subscribe Sign in

Science

Researchers used Anthropic’s Claude to hack into OpenAI

TechCrunch
1 min read Rewritten in plain language

Artificial intelligenceSecurityAnthropicCybersecurityOpenAI

Show what we removed Rules applied: A1×2 A3×3 C2 D2 D3×8 D4 F2×4 all 30 rules
  • In a twist that captures the new state of AI security, independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses, The Wall Street Journal reported on Thursday evening.
  • The team managed to chain together two vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts, which gave them entry into the company’s software.
  • The researchers found a path into OpenAI on July 25 via a flaw in Discourse, the third-party software powering OpenAI’s community forum.
  • The researchers said the Claude model they were using — a special version of Opus 4.8 made available for cybersecurity researchers — couldn’t build a working exploit at first.
  • For example, AI safety nonprofit SaferAI recently found that Chinese company Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

The researchers said the Claude model they were using couldn’t build a working exploit at first. For example, AI safety nonprofit SaferAI recently found Chinese company Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7.

Headline check

All two things this headline claims are in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

Home Server library picture
Not from this story. A library photograph of computer server technology, used to illustrate it. Home Server DeclanTM / flickr, CC BY

In a twist that captures the new state of AI security, independent security researchers have used Anthropic’s Claude to break into OpenAI, exposing cracks in the ChatGPT-maker’s defenses, The Wall Street Journal reported on Thursday evening.

A three-person security team at startup Hacktron AI carried out the attack as part of an OpenAI bug-bounty program. Hacktron reported its findings to OpenAI500 award. The team managed to chain together two vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts, which gave them entry into the company’s software.

OpenAI says it has resolved the issues Hacktron uncovered, which happens to come at a moment when top AI companies are under pressure over safety.

The researchers found a path into OpenAI on July 25 via a flaw in Discourse, the third-party software powering OpenAI’s community forum.

When users posted HEIF or HEIC image files to OpenAI’s community forum, Discourse passed them through a chain of behind-the-scenes tools to convert them into standard JPEGs.

The researchers said the Claude model they were using — a special version of Opus 4.8 made available for cybersecurity researchers — couldn’t build a working exploit at first.

Once inside the Discourse server, the researchers found another flaw that let them take over users’ ChatGPT and Codex accounts, including those belonging to OpenAI workers.

At this point, the researchers alerted OpenAI as well as Discourse, which issued a fix on July 27.

For example, AI safety nonprofit SaferAI recently found that Chinese company Z.ai’s GLM-5.2 was only a few months behind OpenAI’s GPT-5.5 and Anthropic’s Claude Opus 4.7.

Shortened to 1 minute of reading, this version reads 6.1 on the Niral Score.

You are reading our version, not theirs. This is TechCrunch's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingHappiness
TechCrunchas they published this story 11 20 59 50.6
Mundane Readneutralized from TechCrunch 8.5 18 59 50.6

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works