{
  "id": 8192566,
  "title": "This tiny cybersecurity startup managed to hack OpenAI using Claude, and won a $6,500 bounty",
  "url": "https://urgent.news/2026/09/18/this-tiny-cybersecurity-startup-managed-to-hack-openai-using-claude",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T06:46:12.000Z",
  "source": {
    "name": "Business Insider",
    "slug": "business-insider",
    "url": "https://www.businessinsider.com/hacktron-ai-cybersecurity-startup-hack-openai-using-claude-2026-9"
  },
  "original_language": "en",
  "account": "Hacktron, a nascent AI cybersecurity startup in San Francisco, successfully infiltrated OpenAI's codebase using Claude, a powerful language model. Zayne Zhang, co-founder and CEO of Hacktron, disclosed the security lapse to Business Insider. The company identified vulnerabilities in OpenAI's system architecture following a recent hack involving OpenAI and Hugging Face. Zhang's research team began investigating security gaps at prominent AI firms like OpenAI. Hacktron successfully exploited the vulnerability via Claude, gaining access to ChatGPT and Codex accounts of users logging into OpenAI's community help forum. The company then used Claude to propose changes in OpenAI's internal code repository, but stopped short of accessing any code before alerting OpenAI. In exchange for disclosing the issue, Hacktron received a $6,500 bounty. The startup, less than a year old and with fewer than 10 employees, emphasizes the growing convergence of AI safety and cybersecurity, highlighting the importance of cybersecurity professionals in the AI conversation. OpenAI acknowledged the researchers' findings, tightened the permissions on Community sign-in tokens, and revoked affected tokens and sessions. Concerns over rogue AI agents, exemplified by recent disclosures from OpenAI, Anthropic, and Meta, have intensified fears of an AI apocalypse.",
  "summary": "Hacktron, an SF-based startup, flagged vulnerabilities in OpenAI's systems and was paid $6,500 for the discovery.",
  "key_points": [
    "Hacktron, a tiny AI cybersecurity startup, hacked OpenAI using Claude.",
    "Zayne Zhang, CEO of Hacktron, disclosed the security lapse to Business Insider.",
    "Hacktron received a $6,500 bounty for disclosing the issue to OpenAI."
  ],
  "editors_take": "Hacktron's successful hack shows AI safety and cybersecurity are increasingly intertwined, highlighting the crucial role of cybersecurity professionals in mitigating risks associated with powerful language models.",
  "illustration": "https://urgent.news/ill/8192566.png",
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Techmeme",
        "title": "Security researchers in an OpenAI bug bounty program hacked OpenAI, accessing its \"monorepo\" on GitHub, using a cybersecurity version of Opus 4.8 and Opus 5 (Robert McMillan/Wall Street Journal)",
        "url": "https://urgent.news/2026/09/18/security-researchers-in-an-openai-bug-bounty-program-hacked-openai",
        "published": "2026-09-18T04:40:33.000Z"
      },
      {
        "outlet": "Forbes",
        "title": "Security Researchers Hacked Into OpenAI Using Anthropic’s Claude",
        "url": "https://urgent.news/2026/09/18/security-researchers-hacked-into-openai-using-anthropics-claude",
        "published": "2026-09-18T05:26:54.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}