RESEARCH

Security Researchers Used Anthropic’s Claude to Break Into OpenAI in Under 72 Hours

J James Whitfield Sep 18, 2026 2 min read
Engine Score 8/10 — Important

tier-1 research

Editorial illustration for: Security Researchers Used Anthropic's Claude to Break Into OpenAI in Under 72 Hours
  • Three security researchers used Anthropic‘s Claude to break into OpenAI’s internal systems in under 72 hours.
  • They took over employee accounts and reached an internal code repository, then reported the flaws.
  • It is a responsible-disclosure demonstration of AI-assisted offensive security, not a criminal breach.
  • The result shows frontier models can accelerate real-world intrusion, not just theory.

What Happened

Three security researchers used Anthropic‘s Claude models to break into OpenAI’s internal systems in under 72 hours, The Decoder reported on September 18, 2026. They exploited vulnerabilities to take over employee accounts and gain access to an internal code repository before reporting the flaws, according to TechCrunch.

Why It Matters

This is a concrete, timed demonstration that a frontier model can drive a real intrusion end to end, not merely suggest attack ideas. It follows a year of warnings — and Anthropic‘s own reports of models finding and exploiting vulnerabilities — that AI lowers the cost and time of offensive security. That the target was OpenAI, and the tool was a rival’s model, sharpens the point that these capabilities cut across the whole industry.

Technical Details

The reported chain — account takeover followed by access to an internal code repository — is a classic escalation path, compressed into under 72 hours with AI assistance. The researchers followed responsible disclosure, reporting the flaws rather than exploiting them, which is why the account is public. The episode underscores that the same agentic capabilities marketed for defense are directly usable for offense.

Who’s Affected

OpenAI patched the reported flaws, but every organization with internet-facing systems inherits the broader lesson: intrusion timelines are shrinking as models automate reconnaissance and exploitation. Security teams must assume attackers have the same tools. Anthropic and other model makers face renewed pressure over misuse safeguards.

What’s Next

Expect more red-team demonstrations like this one, and continued debate over how labs should gate offensive-security capabilities. The practical defensive response — time-scoped access, credential rotation, and monitoring for automated attack patterns — becomes more urgent as the barrier to intrusion falls.

Share

Enjoyed this story?

Get articles like this delivered daily. The Engine Room — free AI intelligence newsletter.

Join 500+ AI professionals · No spam · Unsubscribe anytime