Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Executive Summary

Researchers at Hacktron used Anthropic’s Claude Opus 5 to chain two vulnerabilities: a bug in OpenAI’s public help‑forum software and a weakness in OpenAI’s login system. The exploit allowed them to hijack ChatGPT and Codex accounts of several OpenAI employees and access an internal code repository. The incident demonstrates how AI can be leveraged to orchestrate multi‑stage attacks on high‑profile targets.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-19T18:36:53+00:00 - Category: threat-intel

Original Description: Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

"A weed is no more than a flower in disguise."

— James Lowell
Source: The Hacker News