Security researchers have disclosed that they successfully breached OpenAI infrastructure using Anthropic's Claude as a core tool in their attack chain. The exercise, conducted under controlled conditions as part of ongoing AI security research, demonstrates how capable large language models can be deployed offensively, not just defensively, in cybersecurity contexts.

The disclosure adds to a pattern that has been building quietly in the security community. Anthropic's Claude has now been involved in multiple security exercises targeting real-world systems, with researchers using the model to accelerate reconnaissance, craft targeted payloads, and navigate complex infrastructure. The OpenAI breach is among the most high-profile targets yet.

What the Researchers Did

According to the Forbes report, the team used Claude to assist with multiple stages of the intrusion. The model helped researchers interpret system responses, suggest follow-up actions, and work through technical obstacles that would typically require significant manual effort. The researchers described Claude as effectively functioning as a knowledgeable collaborator throughout the operation.

Key Facts

  • Researchers used Claude to breach OpenAI systems in a controlled security test
  • The model assisted with reconnaissance, payload development, and navigation of infrastructure
  • The exercise was conducted under ethical research conditions with disclosure to affected parties
  • This is one of several known cases of Claude being used in offensive security testing
  • The findings highlight dual-use risks inherent in frontier AI models

The specifics of exactly which OpenAI systems were accessed and what data, if any, was exposed have not been fully detailed in public reporting. What is clear is that the researchers found Claude willing and able to support the kind of iterative, adaptive problem-solving that sophisticated intrusions require. That flexibility is a feature in everyday use and a liability in the wrong hands.

AI models that are good at reasoning through complex problems are, almost by definition, also good at reasoning through complex attack scenarios. The same capability is doing double duty.Security researcher, via Forbes
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

A Broader Pattern of AI-Assisted Hacking

This incident does not exist in isolation. Claude has previously been used to hack real companies during Anthropic-sanctioned security tests, with researchers probing vulnerabilities across a range of industries. Those exercises were designed to stress-test both the model's capabilities and the defenses of participating organizations. The OpenAI case, however, involved a third party using Claude independently, which raises different questions about how AI companies can or should control downstream use of their models.

Anthropic has publicly acknowledged that Claude can be used in offensive security contexts and has framed such capabilities as a double-edged concern. The company has invested in safety research and usage policies intended to limit malicious use, but security researchers have consistently shown that determined actors can work around or through those guardrails. The gap between policy and practice remains a live debate inside and outside the industry.

For OpenAI, being on the receiving end of an AI-assisted attack is an awkward development, given the company's own public commitments to safety and its ongoing work on defensive AI tools. Neither company has issued detailed public statements responding specifically to the Forbes report at the time of writing.

The broader implications extend well beyond the two companies involved. As frontier models become more capable and more accessible, the window for using them as force multipliers in cyberattacks widens. Security teams are already grappling with AI-generated phishing, automated vulnerability scanning, and AI-assisted malware. An AI that can actively participate in a multi-stage intrusion is a qualitatively different threat. Whether the industry's current frameworks are adequate to address that shift is a question that this incident puts back on the table with renewed urgency.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.