AI Security2026-09-19The Verge

Researchers Used Claude to Hack OpenAI

A team of three independent security researchers at Hacktron reportedly used Anthropic's Claude Opus 4.8 and 5 to break into OpenAI employee accounts in less than 72 hours. According to The Wall Street Journal, the attackers gained access to OpenAI's GitHub repository, known as 'Monorepo.' The incident is a vivid example of the dual-use nature of advanced AI: the same models that help developers write code, find bugs, and automate workflows can also help attackers plan and execute intrusions. The reported success suggests AI is lowering barriers in cybersecurity. Tasks that once required significant manual reconnaissance, such as mapping an organization's employees, identifying credentials, and crafting convincing messages, can be accelerated by language models. If an AI system can connect disparate clues and suggest next steps, a small team may achieve what previously required more people and time. That raises concerns about AI-assisted phishing, social engineering, and automated vulnerability discovery. It also puts pressure on companies to harden identity systems, enforce multi-factor authentication, and monitor for unusual access patterns. At the same time, the use of one company's model against another company's systems raises governance questions. Model providers publish usage policies, but determined users may find ways around them. Security teams increasingly rely on AI for defense, including threat detection and red teaming, so the line between offense and defense is blurry. The researchers' work may be framed as a demonstration, but without responsible disclosure, it could also normalize AI-driven attacks. For OpenAI, the reported breach of employee accounts and repository access will prompt questions about internal security. For Anthropic, it highlights the challenge of preventing misuse. For the broader industry, the lesson is that AI security cannot be separated from ordinary cybersecurity. Multi-factor authentication, least-privilege access, and rapid incident response remain essential. As agentic AI becomes more capable, organizations should assume that attackers will use it to move faster and think in parallel. The Hacktron episode is a reminder that AI safety and AI security are now the same conversation.

Related news