Three cybersecurity researchers have confirmed that they successfully infiltrated OpenAI’s defense system using an advanced AI model from Anthropic. This indicates the risks that artificial intelligence companies and their users face in terms of cyber attacks, with advanced AI models potentially being used as tools by hackers.
According to a report released last week by the cybersecurity company Hacktron AI, the research team was able to breach the accounts of users on OpenAI’s community forum platform, Discourse.
Discourse is a platform where users of ChatGPT and OpenAI’s programming assistant Codex go to seek advice on product-related questions, using their OpenAI accounts to log in.
In a test conducted in late July this year, the research team identified a security vulnerability in the code of the Discourse platform using Anthropic’s Claude Opus 4.8, but they were unsuccessful in exploiting it. However, on the same evening, a more advanced model, Claude Opus 5, was officially released.
The following day, the team successfully accessed the accounts of some OpenAI users on Discourse using Claude Opus 5.
Mohan Pedhapati is one of the three researchers involved in this test. He mentioned that the more advanced AI models make it easier for experienced hackers like himself to conduct their work, while also increasing the risk of criminal elements imitating their actions.
Pedhapati pointed out that the advancement of AI technology has significantly enhanced the efficiency of cyber attacks. He estimated that without AI assistance, carrying out such attacks alone might take two to three months, but with the help of the advanced model Claude Opus 5, the entire process was shortened to less than three days.
He stated, “As language models continue to evolve, their capabilities in the field of cybersecurity become very strong.”
The results of this test show that once researchers gain access to ChatGPT and Codex accounts, they can further access applications associated with these accounts, including email software and the AI workspace platform Slack. They can view all conversations a user has had on ChatGPT.
Those affected include OpenAI employees, whose accounts are also connected to other applications such as the internal OpenAI mailbox.
Pedhapati warned, “Everything you discuss with ChatGPT— we can leak and gain access to. I can see anything you say to ChatGPT, all private or personal information.”
Pedhapati believes that companies should not only protect their core code, as vulnerabilities often exist in deep-seated dependencies, which can spiral and ultimately impact companies using the service. He expressed concerns that major AI laboratories, in their pursuit of development speed, might not meet security defense standards.
Responding to the results of this test, OpenAI has issued a statement thanking Hacktron AI’s research team and has taken steps to patch the vulnerabilities, including reducing the permissions of community login credentials and revoking affected login sessions.
Cybersecurity experts caution that if even small research teams can breach OpenAI’s security defense system within a few days, hackers or criminal groups with national-level backgrounds may find it even easier, posing a threat to the security of AI models, which has escalated to a national security concern.
“I think it’s undeniable that the technology in these labs is directly related to national security. We have seen this from the U.S. government and governments worldwide,” said Nicholas Leiserson, a cybersecurity policy expert at the Security and Technology Institute.
Leiserson pointed out that despite recent statements from some AI industry leaders acknowledging the need to slow down development pace, advancing technology at the forefront quickly has always been the primary mission of laboratories like OpenAI over the years.
“Is this an acceptable and reassuring outcome? Is this the risk standard that our entire society deems appropriate? Because so far, those labs have been the ones defining where that risk line should be, and we have seen where they ultimately draw the line,” he added.
