# Three researchers used Claude to breach OpenAI's code repository in 72 hours, report says

Digest AI · Policy & Regulation · published 2026-09-21T05:36:00Z

Canonical: https://digestai.news/story/three-researchers-used-claude-to-breach-openai-s-code-repository-in-72

## Summary

Security researchers from Hacktron reportedly used Anthropic's Claude to infiltrate OpenAI's code repository in less than 72 hours, according to the Wall Street Journal and TechCrunch. The breach combined a remote‑code‑execution flaw in the Discourse forum software with a misconfigured single sign‑on system, allowing the attackers to move from a public forum account to an employee account and then to the internal GitHub monorepo that stores core model‑running code. OpenAI treated the incident as a bug‑bounty case, issuing a $6,500 reward and leaving a harmless pull request as evidence.

The episode coincided with a week of broader AI safety activity: Sam Altman's safety‑verification essay drew 6.1 million impressions; Google launched Gemini 3.8 Live; Anthropic said Claude now leads 26 % of its R&D; and TypeSafe unveiled the decision‑only model Jev alongside a $40 million seed round. A zero‑click attack dubbed “Plugin4Shell” was also disclosed, highlighting how coding agents are becoming new attack surfaces.

## Key points

- Three Hacktron researchers accessed OpenAI's code repo using Claude in under 72 hours
- Attack chained a Discourse RCE flaw with an SSO misconfiguration to reach the internal monorepo
- OpenAI paid a $6,500 bug bounty for the vulnerability, leaving a harmless pull request

## Why it matters

The breach shows AI assistants can dramatically speed up attacks on critical AI infrastructure, prompting urgent security reassessments.

## Sources

1. [【AI Weekly Report 9/14~9/20】The breach of OpenAI was completed in 72 hours. It was Claude that was used](https://note.com/_kihonushi/n/ne0687a7300d9?hl=en) (note.com, 2026-09-21)

Part of the developing story: [Claude Opus 5 Account Breach Saga](https://digestai.news/thread/researchers-used-claude-opus-5-to-compromise-openai-employee-accounts-report) (3 stories)

## Cite

Digest AI, "Three researchers used Claude to breach OpenAI's code repository in 72 hours, report says", 21 September 2026, https://digestai.news/story/three-researchers-used-claude-to-breach-openai-s-code-repository-in-72

---

Written by Digest AI's editorial model from the linked sources; the sources are the record. Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse
JSON: https://digestai.news/story/three-researchers-used-claude-to-breach-openai-s-code-repository-in-72.json
