ResearchFriday, September 18, 2026· 2 min read

Researchers Use Claude to Uncover OpenAI Security Gaps in 72 Hours

Source: The Verge AI

TL;DR

Independent security researchers reportedly used Anthropic’s Claude to identify and demonstrate access weaknesses affecting OpenAI employee accounts in under three days. While the incident is concerning, the responsible-research angle highlights how AI can help defenders find serious vulnerabilities faster and improve software security.

Key Takeaways

  • 1A three-person Hacktron research team reportedly used Claude Opus 4.8 and 5 during the security test.
  • 2The researchers demonstrated access by sending a pull request from an employee Codex account, while stopping short of accessing internal code.
  • 3The work shows how AI tools can accelerate security research and vulnerability discovery.
  • 4High-profile testing like this can help organizations harden third-party integrations and internal access controls.

AI Speeds Up Responsible Security Research

A team of independent security researchers at Hacktron reportedly used Anthropic’s Claude models to help identify a path into OpenAI employee accounts in less than 72 hours. According to reports, the researchers reached OpenAI’s GitHub environment and demonstrated access without directly reviewing internal code.

The positive takeaway is that AI is becoming a powerful assistant for defensive cybersecurity. Used by responsible researchers, these systems can help map attack paths, analyze complex systems, and surface weaknesses quickly enough for organizations to respond before malicious actors exploit them.

  • Faster discovery: AI can help small teams test systems at greater speed and scale.
  • Safer validation: The researchers reportedly proved access with a pull request rather than extracting sensitive code.
  • Better defenses: Findings like this can drive stronger controls around employee accounts, third-party services, and code repositories.

As AI tools become more capable, their role in security will depend heavily on how they are used. This case illustrates a promising path: AI-assisted research that exposes risks, encourages fixes, and ultimately makes critical digital infrastructure more resilient.

Get AI Wins in Your Inbox

The best positive AI stories delivered to your inbox. No spam, unsubscribe anytime.