OceanAltOceanAlt
Agent Economy2026-09-19Event 2026-09-172 min read

Security Researchers Breach OpenAI Internal Systems via Claude

A three-person team claims it used Anthropic's Claude model to access an OpenAI employee account and a GitHub repository said to contain 'OpenAI's algorithmic secrets' in under 72 hours.

OOceanAlt EditorialSource

Security Researchers Breach OpenAI Internal Systems via Claude

According to The Wall Street Journal, a team of three independent security researchers operating under the name Hacktron claims to have breached an OpenAI employee account in under 72 hours using Anthropic's Claude model. The team reportedly gained access to OpenAI's GitHub code repository known as "Monorepo," which people familiar with the matter say contains "OpenAI's algorithmic secrets."

The researchers did not directly read the code inside Monorepo. Instead, they submitted a pull request through an employee's Codex account to prove they had obtained access. The entry point for the intrusion was Discourse, a third-party forum service.

The incident brings the real-world risk of AI models being used to assist cyberattacks to the forefront, and puts the boundaries of model capabilities and access controls in the spotlight. As of publication, neither OpenAI nor Anthropic has publicly responded.

Source: https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist

Provenance & status

Byline
OceanAlt Editorial
First published
2026-09-19
Last updated
2026-09-19
Content type
Newsflash
Source material
View original ↗

Cite this piece

OceanAlt Editorial (2026). "Security Researchers Breach OpenAI Internal Systems via Claude". OceanAlt. https://oceanalt.com/en/articles/flash-auto-mu77g4l5-98s0 (accessed 2026-09-19)

This piece follows our editorial and fact-checking standards. Found an error? tell us. Once verified, the correction will be published right here.

TRY IT · FREE, NO SIGNUP

Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.

This judgement can sit inside your own product

One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

The widget collects no reader identity. Integrating does not mean OceanAlt endorses your product, or any address on your page.