According to a report by The Wall Street Journal on September 18, independent security researchers successfully hacked into an OpenAI employee's ChatGPT account using Anthropic Claude, gaining access to the company's private software code repository.
The involved team came from the security company Hacktron AI, which had previously participated in OpenAI's bug bounty program. After discovering the vulnerability, the team quickly reported it to OpenAI, which then paid a bounty of $6,500 (approximately 43,692 RMB).
The Vulnerability was on Discourse, and the Token Actually Worked on ChatGPT
The intrusion began on July 23. On that day, Hacktron researchers discovered a vulnerability in how Discourse handled specific image files and used a special version of Claude Opus 4.8, available only to qualified cybersecurity professionals, to request code that exploits this vulnerability—this first attempt failed; that night, Anthropic released Opus 5, and the next day, Claude found a way to exploit it.
The exploited vulnerability is numbered CVE-2026-45788, an unrestricted upload vulnerability in the Discourse secure upload feature. Attackers can expose secure upload content if they know the protected upload URL, without requiring authentication to launch a remote attack. Discourse stated that it was notified on July 25 and fixed the issue the same day.
The attack allowed researchers to access the Discourse server hosting OpenAI's forum and obtain account login tokens. What they did not expect was that these tokens were effective on ChatGPT, including those of OpenAI employees, and could also be used to access OpenAI's GitHub service.
As a result, researchers were able to read files in a large software repository called "Monorepo." According to insiders, Monorepo is the repository where OpenAI stores algorithm secrets to make models faster and more efficient, but it does not contain model weights. They stopped the attack after realizing they could access sensitive data, having previously submitted a document modification request with the label "Hacktron AI Team PoC" as proof (which was not accepted).
"We Are Just Three People with Claude and Codex Subscriptions"
Mohan Pedhapati, CTO of Hacktron AI, said the attack shows that state-sponsored advanced cyber teams indeed have real opportunities to glimpse American AI secrets: "I don't think we are smarter than foreign threats. We are just three people with Claude and Codex subscriptions."
