News

Three Hackers Used Anthropic's Claude to Break Into OpenAI's Private Source Code for $6,500

Hacktron AI researchers disclosed a bug-bounty path into OpenAI employee ChatGPT accounts and GitHub, first reported via the Wall Street Journal on 18 September 2026. OpenAI paid $6,500 and said it addressed the vulnerabilities after sources described a repository area named Monorepo as the company's secret sauce for model speed.

Three Hackers Used Anthropic's Claude to Break Into OpenAI's Private Source Code for $6,500

Fortune (18 September 2026) reported that OpenAI paid $6,500 under its bug bounty program to researchers who reached the company's private source code with help from Anthropic's Claude. The Guardian carried the same Wall Street Journal origin reporting the same day.

This is an ethical bug-bounty disclosure by three researchers at Hacktron AI. It is not a nation-state raid, not a customer data breach, and not a CVE assignment.

The team first used Claude to help open a path through a Discourse-hosted OpenAI staff discussion forum, then reached employees' ChatGPT accounts and OpenAI's GitHub software repository. They later said they were largely using OpenAI's own GPT-5.6 Sol model, plus Codex subscriptions, after that first Claude assist.

Sources told the Journal they reached a repository area named Monorepo, described as OpenAI's "secret sauce" that makes models run faster. That description is colour from those sources, not an OpenAI product page. The researchers made a harmless pull request and said they accessed the code but did not download it. Hacktron said, "The scope of what we could theoretically access was huge."

Mohan Pedhapati of Hacktron told the Journal, "We're just three guys with Claude and Codex subscriptions." Hacktron said work that once needed a well-resourced team and months can now be compressed into days.

An OpenAI spokesperson thanked the researchers for sharing their findings and said the exploited vulnerabilities were addressed. OpenAI recently disclosed rogue-agent activity around Hugging Face tests and more "unexpected or concerning" model actions. Anthropic and peers called for a development slowdown. Donald Trump rejected that framing, citing competition with China.

Related incident tape includes OpenAI rogue agents on Hugging Face, Anthropic's fourth Claude cyber incident, and Plugin4Shell in AI coding agents.

If you run a staff forum tied to GitHub or ChatGPT single sign-on this week, cut that forum off the employee identity path and treat a bounty pull request as the alert that private repos were reachable, not as proof that customer data left the building.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free