A three-person team from the cybersecurity start-up Hacktron AI gained access to OpenAI employees' ChatGPT accounts using an artificial intelligence model developed by Anthropic, according to a post published on the start-up's website on Thursday. OpenAI confirmed the intrusion to AFP, describing it as part of a security exercise it had itself commissioned to identify vulnerabilities in its systems with the help of external cybersecurity specialists.
How the researchers gained access
The intrusion took place in late July. To achieve their goal, the team used Discourse, a messaging platform used internally by OpenAI that allows employees to log into their ChatGPT or Codex accounts, the latter being OpenAI's AI coding tool. Through this method, the researchers managed to access a number of employee accounts.
Since users can grant ChatGPT or Codex permission to interact with multiple applications and files, "the scope of what we could theoretically access was enormous," the team explained, citing GitHub, the code repository platform, Slack, the workplace messaging tool, and email accounts among the systems potentially exposed.
An older model struggled, a newer one found the flaw in hours
The team's account highlights the pace at which AI models are advancing. The researchers began their attempt using Claude Opus 4.8, a model Anthropic released in May, but this AI "struggled" to find an entry point through Discourse. Coincidentally, Anthropic released a new model, Opus 5, on the same day. This newer model found the security gap "within three hours," according to the researchers.
The team promptly alerted OpenAI, which fixed the vulnerabilities, a company spokesperson said. "We thank the researchers who contacted us and shared their observations," OpenAI told AFP.
A model Anthropic itself restricted over safety concerns
The exercise underscores the growing role of artificial intelligence in cybersecurity. In early April, Anthropic had chosen not to release its Mythos model widely, judging it too dangerous from a cybersecurity standpoint. Access was instead limited to a small number of companies and organisations, allowing them to use the model to identify and fix vulnerabilities in their own software.
Anthropic went on to release a limited version of Mythos, called Fable, in June. Days later, the US governmentsuspended Fable, citing a risk to national security, before approving it again two weeks later.
Source: AFP


