Researchers Used Anthropic’s Claude to Discover Vulnerabilities in OpenAI Systems

Security researchers used Anthropic’s Claude AI model to uncover vulnerabilities in OpenAI systems during a bug bounty investigation.

Sep 18, 2026 - 16:09
 3
Researchers Used Anthropic’s Claude to Discover Vulnerabilities in OpenAI Systems
Image Credit: TechAmerica.ai / AI-generated image

Security researchers used Anthropic’s Claude AI model to uncover vulnerabilities in OpenAI systems during a bug bounty investigation, highlighting how AI tools are becoming part of both cybersecurity defence and vulnerability research.

A three-person team from Hacktron AI conducted the research as part of OpenAI’s bug bounty program. The findings, first reported by The Wall Street Journal, earned the researchers a $6,500 reward from OpenAI.

Claude Helped Researchers Find a Path Into OpenAI Systems

The researchers discovered a chain of two vulnerabilities that let them access multiple OpenAI employee ChatGPT accounts and enter parts of the company’s software environment.

The initial entry point stemmed from a vulnerability in Discourse, the third-party platform used for OpenAI’s community forum. Hacktron found that specially crafted image uploads could exploit a weakness in the platform’s image-processing software chain. 

According to Hacktron’s technical write-up, the issue involved a flaw in libheif, a software library used to process HEIF and HEIC image files. The vulnerability let researchers run their own instructions on the affected server.

The researchers said the underlying libheif issue had already been fixed by developers, but the update had not been formally tracked as a security vulnerability through a CVE identifier. Hacktron suggested this may have contributed to vulnerable software remaining in use.

AI Models Are Changing Cybersecurity Research

Hacktron said the Claude model used during the research initially struggled to create a working exploit. However, after Anthropic released a newer model version, the researchers said it solved the challenge within hours. The team shared the details in its analysis of the model’s performance.

The incident has raised questions about how easily advanced AI models can help security researchers, attackers, and organisations testing their own defences.

An AI security discussion following the report highlighted concerns about what such capabilities could mean if more powerful threat actors used them, as discussed in a social media post.

Growing Focus on AI Security

OpenAI said it fixed the vulnerabilities after researchers notified it. The disclosure comes as AI companies face increasing pressure to improve security practices as their models become more capable.

Hacktron founder Mohan Pedhapati said AI is reducing the expertise and time required to develop exploits. He shared his view on how AI is changing cybersecurity research in a post on X.

The incident demonstrates how AI systems can become powerful tools for security testing while also creating new challenges around protecting advanced technology platforms.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav’s current bio says she reports on technology-focused developments “in India”, but the same profile publishes stories about U.S. NHTSA investigations, Hugging Face, global AI startups and other international topics.