Several months ago, cybersecurity specialists from **Hacktron AI**, a U.S.-based startup established in 2025, carried out an ethical hacking exercise that breached the internal systems of **OpenAI**, a company known for developing the **ChatGPT** language model. The operation, conducted as part of a "Bug Bounty" program, involved using **Claude**, an AI developed by **Anthropic**, a competitor of OpenAI. **Hacktron AI**, which focuses on AI-driven cybersecurity and provides an automated platform for penetration testing and code review, detailed the operation in a blog post published on September 13, 2026. The purpose of the exercise was to show how artificial intelligence is changing the speed and ease with which cyberattacks can be carried out.
The team targeted **Discourse**, a messaging platform used internally by OpenAI, which allowed employees to access their professional **ChatGPT** or **Codex** accounts. **Hacktron AI** identified a vulnerability in this authentication system and gained direct access to the internal employee accounts. According to the blog post, the novelty of the ethical attack was the use of **Claude** to analyze the target's infrastructure. The AI then generated custom attack code to exploit the known flaw, greatly reducing the time and resources needed for the operation. Typically, such a task would have required weeks of effort and substantial resources, especially considering that the **Hacktron AI** team consists of just three people.
After gaining access to the private source code and internal accounts, the experts alerted **OpenAI** directly. The company became aware of the proof of concept and paid **Hacktron AI** $6,500 as part of its "Bug Bounty" program. In their communication, **Hacktron AI** mentioned that they sent an instruction (prompt) to an employee's **Codex** account, asking him to open a pull request in **OpenAI**'s internal monorepo, but then halted the tests. The startup emphasized that the ethical hacking operation highlights how AI significantly lowers the barrier for entry into cyberattacks. It argued that this development should prompt cybersecurity professionals to speed up the deployment of defensive AI to address vulnerabilities more quickly, ideally before they are discovered.
Ethical Hackers Use Competitor AI to Exploit OpenAI System Vulnerability
AI-rewritten from original reportingHow it works
aicybersecuritybug-bountyopenaihacktron-aiethical-hacking



