A small research team just proved something unsettling. Using Anthropic's Claude Opus 5, three researchers at Hacktron AI broke into OpenAI's internal systems in under 72 hours. This AI hacking story, first reported by the Wall Street Journal, shows how far AI-assisted security research has come, and how exposed even top AI labs remain.

The work was authorized. It was a legitimate bug bounty exercise, not an attack. But the speed and precision behind it are worth a closer look.
The researchers started with OpenAI's community forum, community.openai.com, which runs on Discourse software. They found a weakness in how the forum handled certain image uploads, tracing back to an outdated image-decoding library called libheif inside ImageMagick.
Claude played a direct role in building a working exploit for that flaw, according to reporting from hacktron.ai. Earlier model versions struggled with the task, but Opus 5 handled it reliably. It’s a detail that's central to why this Claude and OpenAI story stands out from typical bug bounty reports.
Here's how the chain came together:
Researchers found a heap buffer overflow in libheif through Discourse's image pipeline
Claude helped develop and refine a working exploit for the flaw
The team paired this with a separate SSO misconfiguration on OpenAI's side
Combined, both issues allowed takeover of ChatGPT and Codex accounts tied to SSO logins
Some affected accounts belonged to OpenAI employees with GitHub access
One hijacked Codex account was used to open a harmless pull request inside OpenAI's internal codebase, proving impact without touching sensitive data
The entire process, from discovery to proof of access, took less than three days in late July 2026, based on details provided by the report. In plain terms, OpenAI hacked its own defenses into a real-world stress test, and the results traveled fast through security circles.
What stands out most is the jump in capability between model generations. Work that once required deep specialized expertise and weeks of effort got compressed into days. That's not a small shift. It changes the math for both defenders and attackers.
Small, skilled teams paired with strong coding models can now match results that used to demand much larger resources. Security teams everywhere need to factor that into their threat models, especially around patch timing and access controls.
AI agents keep closing the gap between human expertise and automated capability.
Once the vulnerability was reported through Bugcrowd, OpenAI moved fast. The SSO issue was fixed within 14 hours. A $6,500 bounty was paid, even though the Discourse-hosted forum sat outside the formal bounty scope. Discourse and Debian issued their own patches shortly after, and additional sandboxing was added.
No customer data or model weights were accessed at any point. That detail matters. It shows responsible disclosure still works, even when the underlying exploit chain is this sophisticated.
This story reaches beyond OpenAI's internal codebase. The same capability jump that helped researchers chain a forum bug with an SSO flaw could just as easily target crypto infrastructure. Wallet extensions, trading bots, and exchange login systems all rely on similar web architecture, third-party libraries, and identity setups.
As AI coding agents get better at finding and exploiting these weak points, crypto platforms face the same pressure OpenAI just experienced. Outdated dependencies, over-privileged accounts, and weak identity controls remain common across the industry, and they're exactly what tools like Anthropic’s Claude AI can now probe faster than ever.
The bigger picture is clear. Claude vs OpenAI isn't really a rivalry story. It's a preview of how AI is becoming a genuine force multiplier for both security research and exploitation, depending on who holds the keyboard.
Companies building AI products, and companies securing crypto assets, need to treat rigorous patching, least-privilege access, and strong identity controls as non-negotiable.
This AI hacking story won't be the last one. It's a signal of how fast the ground is shifting under everyone's feet.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.