A group of cybersecurity researchers infiltrated OpenAI's internal systems by leveraging Anthropic's Claude, an AI assistant designed for security professionals. The breach gave them access to an employee's ChatGPT account, exposing private software repositories and source code to unauthorized eyes.

What You Need to Know

The researchers acted as part of a paid vulnerability discovery program that provided them with Anthropic's security-focused tool. By using Claude, they gained entry to an OpenAI employee's ChatGPT account, where they could read proprietary software and even suggest changes. This incident reveals a new class of risk: AI models that are designed to secure systems can also be turned against rivals.

The Breach in Detail

The breach unfolded when the researchers, equipped with access to Claude, targeted OpenAI’s infrastructure. They exploited a flaw in how ChatGPT sessions handled authentication, allowing them to take over an employee’s account. Once inside, the team could browse internal code and comment on potential improvements.

This attack did not rely on traditional phishing or malware. Instead, it used the AI assistant’s own capabilities to navigate and interact with the target systems. The researchers, contracted by Anthropic under a bug bounty program, were paid to find such weaknesses before malicious actors could exploit them.

  • Account Compromise: The researchers accessed a ChatGPT account belonging to an OpenAI employee.
  • Data Exposure: They could view private software repositories and internal code.
  • Modification Capability: The breach allowed them to propose changes to the system.

Why This Matters

The security incident carries significant consequences for both OpenAI and the broader AI industry. For OpenAI, it demonstrates that even internal employee accounts are vulnerable to attacks that use AI tools as weapons. The breach could erode trust among enterprise customers who rely on ChatGPT for sensitive work.

For Anthropic, the episode raises questions about dual-use risks. A tool built to strengthen security was used to compromise a competitor. Regulators and industry groups are likely to demand stricter controls on how AI models are distributed and used across organizations. The incident may accelerate calls for ethical boundaries in bug bounty programs, especially when tools from one company are used against another.

Industry Implications

This breach highlights a growing tension between collaboration and competition in AI. Companies like OpenAI and Anthropic share some security goals, yet their tools can be repurposed for attacks. The researchers’ success shows that defensive AI can become offensive with little modification.

Moving forward, AI firms may need to implement more robust session isolation and monitor for anomalous use of their own models. The event also underscores the importance of cross-platform vulnerability research. As AI assistants become more powerful, the line between friend and foe in cybersecurity will continue to blur.