Three security researchers used Anthropic's Claude as a core tool in a successful hack against OpenAI, gaining access to the company's source code and collecting a $6,500 bug bounty reward in the process. The exploit, reported by Fortune, highlights the growing role AI assistants are playing in offensive security research, for better or worse.

How the Hack Unfolded

The researchers, working as a team, used Claude to help identify and exploit vulnerabilities in OpenAI's infrastructure. The details of the specific techniques remain limited, but the core takeaway is straightforward: an AI model made by one of OpenAI's primary competitors was used as a key instrument in breaching OpenAI's systems. The team ultimately got inside far enough to view source code before reporting the issue through legitimate channels. OpenAI's bug bounty program then paid out the $6,500 reward, effectively validating the severity of what the researchers found.

Key Facts

  • Three researchers collaborated on the hack using Claude as an AI assistant
  • They accessed OpenAI source code during the operation
  • OpenAI paid $6,500 through its official bug bounty program
  • The disclosure followed responsible reporting procedures
  • The incident adds to a growing body of cases involving Claude in security contexts

Bug bounty programs exist precisely to incentivize this kind of disclosure. Researchers find a vulnerability, report it privately, and receive compensation in exchange for not weaponizing what they found. The system worked as intended here, even if the method raises eyebrows. Using a rival company's AI model to attack your own systems is an unusual wrinkle that neither Anthropic nor OpenAI has publicly commented on in depth.

The researchers accessed OpenAI source code and were paid $6,500 for their findings through the company's bug bounty program.Fortune
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

Claude's Expanding Role in Security Research

This incident is not entirely isolated. There is a broader pattern forming around Claude's involvement in security testing. Earlier this year, coverage emerged showing that Claude hacked three companies during sanctioned cyber tests, raising questions about how capable the model has become in adversarial scenarios. Those cases involved controlled environments, but the line between controlled research and real-world exploitation is one the industry is actively debating.

For the latest Claude AI news, the OpenAI incident fits into a pattern where Claude's coding and reasoning abilities make it a capable assistant for technical security work. Penetration testers and red teams are increasingly turning to large language models to help automate reconnaissance, draft exploit code, and reason through complex attack chains. Claude, with its strong performance on coding tasks, is a natural fit for that kind of workflow.

What makes this case distinct is the target. OpenAI and Anthropic are direct competitors in the AI market, both racing to build capable frontier models. The idea that Claude, Anthropic's flagship model, served as a tool to expose weaknesses in OpenAI's codebase carries an obvious irony. It also underscores that AI capabilities don't respect corporate boundaries. Researchers will use whatever tool works best, regardless of who built it.

What This Means Going Forward

The $6,500 payout is modest by bug bounty standards, but the story carries weight beyond the dollar figure. It signals that AI-assisted hacking is no longer theoretical. Researchers are actively using models like Claude to shorten the time it takes to find and chain together vulnerabilities. Security teams at major AI companies now face an adversarial landscape where their competitors' tools could end up being used against them.

OpenAI has not disclosed whether it will adjust its bug bounty terms in response to AI-assisted submissions. Anthropic, for its part, has not indicated any plans to restrict Claude's use in security research contexts, though the company does maintain usage policies that prohibit malicious exploitation. What the researchers did fell within legitimate bug bounty work, which keeps it on the right side of those policies, at least for now.

As AI models grow more capable, the security community will keep probing what they can do. This episode is a data point in that ongoing experiment, and it won't be the last.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.