Three independent security researchers from Hacktron successfully breached OpenAI employee accounts in under 72 hours by deploying Anthropic’s Claude Opus 4.8 and 5 models. The team targeted a vulnerability within Discourse, the third-party platform hosting OpenAI’s community forums, to gain entry to the company’s internal systems. They did not extract sensitive code from the Monorepo repository themselves but instead submitted a pull request from a stolen Codex account to demonstrate their access. This action confirmed that the artificial intelligence models could be directed to identify weak authentication methods and execute specific commands to compromise corporate credentials. The incident highlights a growing risk where large language models are weaponised for targeted social engineering rather than general assistance. Security teams must now consider how AI agents might exploit specific platform weaknesses to bypass traditional security protocols. This case serves as a stark warning about the potential for generative AI to automate complex cyberattacks against major technology firms.
- The breach occurred using Claude Opus 4.8 and 5 models.
- Access was gained through the Discourse community platform.
- A pull request from a stolen Codex account proved the breach.




