A group of researchers has successfully used Anthropic's Claude to breach systems belonging to OpenAI, according to a report from TechCrunch. The incident, framed as a security research exercise, demonstrates how capable AI assistants can be repurposed as tools for offensive cybersecurity operations, even when the target is another leading AI company.

The research adds to a growing body of evidence that large language models can meaningfully assist with complex technical attacks. As covered in our earlier reporting on how security researchers used Claude to successfully hack ChatGPT, this is not an isolated finding. The pattern suggests AI models are becoming practical instruments in the hands of both ethical researchers and, potentially, malicious actors.

How the Attack Unfolded

While full technical details remain limited in public disclosures, the researchers reportedly used Claude to assist in identifying vulnerabilities, crafting attack strategies, and executing steps that ultimately gave them access to OpenAI systems. The approach leaned on Claude's ability to reason through multi-step technical problems, which security professionals have noted makes it particularly useful for penetration testing workflows.

Key Facts

  • Researchers used Anthropic's Claude as the primary AI tool in the attack
  • The target was infrastructure or systems associated with OpenAI
  • The exercise was conducted as security research, not a malicious breach
  • The findings were reported via TechCrunch, citing the research team's work
  • The incident raises questions about AI safety guardrails in offensive security contexts

The fact that Claude was used against a direct competitor of Anthropic makes the story particularly pointed. Both companies occupy the top tier of the generative AI industry and have each invested heavily in safety research. That one company's model could be used to probe the other's defenses underscores how AI capabilities cut across competitive boundaries.

AI models trained to be helpful, harmless, and honest can still be steered toward security research tasks that carry real offensive potential, depending on how requests are framed and what guardrails are in place.Security Research Context, TechCrunch
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

Implications for AI Safety and Policy

The episode arrives at a sensitive moment for the AI industry. Companies like Anthropic and OpenAI have both publicly committed to responsible AI development, and questions about dual-use risks have intensified in recent months. As discussions around AI governance have moved into international forums, with Anthropic, OpenAI and Google CEOs appearing at the G7, incidents like this one provide concrete examples policymakers can point to when arguing for stronger oversight of AI capabilities.

For Anthropic specifically, the situation is complicated. The company's entire public identity is built around safety-first AI development. Claude being used to hack another organization, even in a research context, tests the limits of how safety messaging holds up when models are applied in adversarial settings. Anthropic has not publicly commented on this specific research as of publication.

The research team's findings are consistent with what other groups have documented recently. A separate study examined in detail how three Indian researchers used Claude to hack OpenAI systems, suggesting this line of security inquiry has attracted multiple independent groups working in parallel. Together, these reports paint a picture of Claude being tested, deliberately, against some of the most fortified AI infrastructure in the world.

Whether Anthropic will respond with updated usage policies, tighter guardrails on security-adjacent prompts, or public guidance for the research community remains to be seen. What is clear is that the boundary between AI assistant and AI attack tool is thinner than many had assumed, and the security community is paying close attention to where that line sits across different models and configurations.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.