Researchers Used Claude to Reach OpenAI Employee Accounts and Code

Researchers Used Claude to Reach OpenAI Employee Accounts and Code

Claude was reportedly used to reach OpenAI employee accounts and sensitive internal code in less than 72 hours. That makes this more than an AI capability story: it is a concrete test of how quickly capable models can turn vulnerabilities into access.

The reported incident matters because the access claim is specific. But it does not yet establish the full scope of compromise, user impact, or whether the method will work broadly elsewhere.

Claude Turned Capability Into Access

Security researchers at Hacktron reportedly used Anthropic’s Claude to exploit vulnerabilities in OpenAI systems.

According to TechCrunch, the researchers took over employee accounts and accessed an internal code repository before reporting the flaws. Ars Technica similarly described access to an OpenAI employee account and sensitive GitHub data.

The important shift is operational. A model-assisted workflow appears to have helped move from finding weaknesses to reaching sensitive systems. That puts the security focus on the entire path from reconnaissance through exploitation and account access—not only on the public-facing AI product.

The 72-Hour Constraint

The Verge reported that three independent Hacktron researchers completed the work in under 72 hours using Claude Opus 4. CBS News also reported a sub-72-hour timeline for penetration of ChatGPT.

Speed is the signal here.

A vulnerability that requires extensive specialist effort creates one kind of risk. A vulnerability that can reportedly be investigated, developed, and exploited inside a few days creates another. The relevant constraint is no longer simply whether flaws exist; it is whether AI compresses the time needed to turn them into a usable attack path.

The Attack Surface Is Now the Workflow

Internal employee accounts and code repositories sit behind the systems users see. Access to them can expose sensitive operational material even when the public application itself remains available.

That creates a broader test for AI security: can a capable model accelerate the workflow around an attack?

- Finding and connecting clues across systems - Developing and refining exploit ideas - Navigating from an initial foothold to privileged resources

The reports suggest that question now deserves attention as a practical security constraint. More capable models may change the pace at which attackers can coordinate work, even if they do not independently create a new vulnerability.

Access Is Not Yet Impact

The available reporting supports meaningful reported access. It does not establish how much data was taken, whether any code was altered, whether users were affected, or whether the researchers’ method generalizes to other companies or models.

That distinction matters. This is a credible demonstration of exposure and capability, not proof of a broad compromise or a settled industry-wide pattern.

Remediation Will Set the Real Precedent

The next evidence should come from the vulnerabilities themselves: what OpenAI fixed, what safeguards changed after disclosure, and whether the result depended on unusual weaknesses or a repeatable AI-assisted method.

A comparable incident at another target would make this a security benchmark. Until then, the durable takeaway is narrower but still serious: reported access to employee accounts and internal code shows that AI-assisted security risk has moved from abstract concern to a concrete operational question.