AIToday
Large Language ModelsAI Safety & AlignmentArs Technica AIPublished: Sep 19, 2026, 01:00 JST

Researchers used Claude to hack OpenAI, reaching GitHub code

Researchers used Claude to hack OpenAI, reaching GitHub code

3 Key Points

  1. What happened

    Researchers reached an OpenAI employee's ChatGPT account and internal GitHub code via a flaw in OpenAI's community forum, hosted by third party Discourse, and OpenAI says it fixed the issues.

  2. Why it matters

    An employee account with internal code access was reachable through a forum setup, so third-party-hosted services appear to be a soft point in defending AI firms' internal code.

  3. What to watch

    The disclosure came as Anthropic reported that 26 percent of R&D work was "led by" Claude, up from 1 percent in March, though its models did not yet operate fully autonomously.

WHO IT HITSSecurity teams at AI labs and other firms that run employee-facing apps through third-party platforms, such as forums, may need to re-examine how those sign-ons link to internal code and ChatGPT accounts.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

The OpenAI disclosure, first reported by The Wall Street Journal, centered on how a third-party forum setup could lead to an employee's ChatGPT account and internal GitHub code. OpenAI thanked the researchers for sharing their findings and said it fixed the issues, while Anthropic declined to comment and Hacktron did not immediately respond.

The same Thursday, Anthropic published data showing its own reliance on AI in model development. It said 26 percent of research and development work was "led by" Claude, up from 1 percent in March, meaning AI completed the majority of tasks under human instruction and supervision. Anthropic said it shared the data to help the public understand how close the world is to recursive self-improvement, the point where AI can train and improve itself or new models, a threshold tied to concerns about losing human control. It added that its models did not yet operate fully autonomously for any of the research studied, and that on 90 percent of tasks AI collaborates with a human and does large chunks of work.

Taken together, the two threads point to a security question that may prove harder to answer than the forum fix itself: as AI systems take on more of the work of building the next version of themselves, the accounts and code they touch appear to sit behind third-party services that can be misconfigured. For OpenAI's security staff, the test is likely whether such third-party links to internal code are removed or merely patched; for Anthropic, the figure to watch is how the share of AI-led R&D work moves beyond the March 1 percent baseline.

FAQ
How did the researchers get into OpenAI's systems?
They exploited a flaw in the set-up of OpenAI's community forum, hosted by third party Discourse, per the article.
What did the ChatGPT account let them reach?
The account had access to internal code through GitHub.
What did Anthropic say about AI doing its own research?
Anthropic said 26 percent of research and development work was "led by" Claude, up from 1 percent in March.
Ars Technica AIRead Original Article

Also reported by THE DECODER, TechCrunch AI

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Prism ML shrinks Qwen3.8 into 5.9GB Bonsai 2 27BSiliconANGLE AI · 23m ago
  • CoreWeave's first user conference set for Sept. 30-Oct. 1SiliconANGLE AI · 23m ago
  • HarnessRouter standardizes agent runs via one protocolDaily Dose of Data Science · 23m ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAmodei: We Understand Only a Tiny Fraction of AI Models