AIToday
Large Language ModelsAI Coding AssistantsAI Safety & AlignmentFortune AIPublished: Sep 18, 2026, 22:00 JST

OpenAI pays $6,500 to team that breached its GitHub

OpenAI pays $6,500 to team that breached its GitHub

3 Key Points

  1. What happened

    OpenAI paid $6,500 through its bug bounty program to Hacktron AI, whose three-person team used Anthropic's Claude to get into OpenAI's GitHub software repository and find a source-code part called "Monorepo."

  2. Why it matters

    The reward covered a breach of OpenAI's own repository, and sources told the WSJ that the Monorepo component is the "secret sauce" that makes OpenAI's models operate faster.

  3. What to watch

    The result hinges on what those sources say about Monorepo's role, since OpenAI's own description is not stated. Watch whether more of this long series of disclosed hacks follows.

WHO IT HITSAI companies running bug bounty and security review programs face a widening gap: models are surfacing cybersecurity holes faster than those holes can be patched.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

This episode sits inside a longer, documented pattern. The article notes a long series of hacks and security breaches perpetrated by, and targeting, both OpenAI and Anthropic, and disclosed by both companies. Both have called for safety guardrails so AI can be developed at a pace that allows humans to review security threat capabilities before models are released to the public.

The mechanism behind this particular breach is what makes it notable. The Hacktron AI team used Anthropic's Claude, and one of its members described the setup plainly to the WSJ: "We're just three guys with Claude and Codex subscriptions." OpenAI's GitHub repository held a source-code component the WSJ's sources called "Monorepo," described as the "secret sauce" that makes OpenAI's models operate faster.

Taken together with the article's observation that AI models are finding cybersecurity holes faster than they can be patched, the outcome looks likely to keep pressure on how these companies structure their bounty and disclosure programs. Whether "Monorepo" proves to be a meaningful exposure or a narrowly scoped one remains unclear from the article alone, since OpenAI's own characterization is not stated.

FAQ
How much did OpenAI pay for the hack, and why?
OpenAI paid $6,500 as part of its bug bounty program. The payment rewarded Hacktron AI, which had broken into OpenAI's GitHub software repository.
What did the hackers find inside OpenAI's repository?
They found a part of OpenAI's source code named "Monorepo." Sources told the WSJ that Monorepo is OpenAI's "secret sauce" that makes its models operate faster.
Who was behind the attack?
A three-person team at Hacktron AI, which used Anthropic's Claude. "We're just three guys with Claude and Codex subscriptions," Mohan Pedhapati of Hacktron AI told the paper.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Anthropic: Claude leads 26% of its AI R&D workITmedia AI+ · 5h ago
  • Benioff calls Nvidia 'exquisite' as Koa model unveiledYahoo Finance AI · 5h ago
  • Atlassian CEO Mike Cannon-Brookes: AI-native clients spend moreSemafor Tech · 5h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAmodei slowdown call hits Kioxia shares, down over 10%