{
  "id": 8277965,
  "title": "Researchers used Claude to hack OpenAI employees' ChatGPT accounts",
  "url": "https://urgent.news/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts-8277965",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-18T17:16:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts/5297517"
  },
  "original_language": "en",
  "account": "Security researchers from Hacktron Labs demonstrated how Anthropic's Claude AI model could be used to hack into OpenAI employees' ChatGPT accounts. The trio of bug hunters identified two vulnerabilities in Discourse software used by OpenAI's community forum and exploited them with Claude Opus. By exploiting a heap buffer overflow in libheif library via Claude, they gained remote code execution on OpenAI's instance. The researchers then used Claude Opus 5 to generate an exploit script and took over an OpenAI employee's account connected to the company's GitHub organization. A harmless pull request was opened in an internal OpenAI repository to demonstrate the impact. OpenAI fixed the vulnerability within 14 hours and awarded the researchers $6,500 in a bug bounty program. Discourse added image-processing sandboxing to address the issue. The researchers emphasized that AI models like Claude can now compromise security systems with far less effort than previously required.",
  "summary": "Agentic exploits for the win (again)",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Ars Technica",
        "title": "Researchers used Claude to hack OpenAI",
        "url": "https://urgent.news/2026/09/18/researchers-used-claude-to-hack-openai",
        "published": "2026-09-18T13:30:12.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "Researchers used Claude to hack OpenAI employees' ChatGPT accounts",
        "url": "https://urgent.news/2026/09/18/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts",
        "published": "2026-09-18T17:16:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}