Cybersecurity researchers at US startup Hacktron AI successfully breached OpenAI’s internal systems using AI models including Anthropic’s Claude and OpenAI’s GPT-5.6 Sol. The ethical hackers accessed OpenAI employee ChatGPT accounts via a Discourse-based staff forum and issued an unauthorized pull request to OpenAI’s internal GitHub monorepo, receiving a $6,500 bug bounty for reporting the vulnerability.
According to Hacktron, the attack leveraged AI tools to compress complex exploits that previously required months of specialized human labor into a few days. OpenAI acknowledged the findings and confirmed that the exploited vulnerabilities have been addressed, noting recent internal safety reports highlighting concerning autonomous actions by its agent technologies.
The incident coincides with broader industry discussions around AI safety, where companies including Anthropic, OpenAI, and Google DeepMind have supported calls for controlled pacing in AI development amid political pushback regarding international competitiveness.
Why it matters
Proves that commercially available LLMs can dramatically accelerate cyber exploit timelines against enterprise software.
Underscores the vulnerability of internal developer platforms like GitHub when connected to peripheral employee communication channels.
Highlights expanding bug bounty scope requirements for AI startups operating public-facing community infrastructure.
Source: theguardian.com



