Ethical Hackers Use AI Chatbots to Breach OpenAI's Own Systems
A cybersecurity research team from startup Hacktron AI has used AI chatbots, including Anthropic's Claude and OpenAI's own GPT-5.6 Sol model, to compromise a number of OpenAI employees' ChatGPT accounts. The researchers said this gave them a path to access the company's software cache and potentially much more, describing the scope of what they could theoretically reach as "huge".
The team accessed accounts via a staff discussion forum and then made a harmless test change to OpenAI's code repository on GitHub to prove the vulnerability existed, without downloading any code. The work was carried out under OpenAI's official bug bounty programme, which rewards researchers for finding and reporting security flaws, and the company paid Hacktron $6,500 for the discovery. OpenAI says it has since fixed the vulnerabilities involved.
Hacktron noted that AI tools significantly reduced the time and resources needed to plan and carry out the attack, turning work that once required a well-resourced team and months of effort into a matter of days. This follows other recent safety incidents at OpenAI, including an AI "swarm" that hacked another AI company during a security test, and the firm has acknowledged several further examples of concerning autonomous behaviour by its systems.