AI · Sep 18, 2026
Security researchers used Claude to help them hack into OpenAIResearchers used Claude to hack OpenAI
Sep 18, 2026, 6:30 AM · Ars Technica

Ars (via Financial Times) adds that Hacktron’s Claude-assisted break-in reached an employee ChatGPT account with GitHub code access—and lands as Anthropic says Claude now leads 26% of its R&D work, up from 1% in March.
Why it matters
Same bounty, sharper stakes: researchers used an Anthropic cyber tool to reach OpenAI internal software information and suggest code changes through an employee account.
OpenAI paid $6,500, fixed the issues, and thanked the researchers. The timing—weeks after OpenAI agents hacked Hugging Face—keeps security and recursive improvement in the same headline frame.
Anthropic’s parallel disclosure that Claude leads 26% of R&D (from 1% in March) makes the recursive self-improvement debate less theoretical while a rival’s model is proving it can crack lab defenses.
From the desk
We’re pairing the break-in with Anthropic’s R&D share number because they belong in one conversation.
FT/Ars emphasize what the employee account unlocked: private software information and suggested changes, with Codex wired to OpenAI’s GitHub organization. The entry remained Discourse on the community forum. Anthropic declined comment; OpenAI confirmed the fix.
Separately, Anthropic published that 26% of research and development work is now “led by” Claude—majority of tasks under human instruction and supervision—up from 1% in March. On 90% of tasks, AI still collaborates with a human. The company framed the data as helping the public see how close recursive self-improvement is. Models aren’t fully autonomous on the studied research yet. They are already doing most of the work on a rising share of tasks.
Useful AI that accelerates lab research is genuine progress. The harm if oversight lags: the same capability class that shortens exploit development also shortens the loop from model to next model. Temporary U.S. blocks on some Anthropic tools already showed how nervous governments are about cyber-capable releases. I’m watching whether recursive-R&D metrics and bug-bounty exploits force harder access gates—or just more press cycles.
Context
Ars Technica / Financial Times, September 18, 2026. Complements TechCrunch’s Discourse/libheif technical path with FT’s GitHub-access emphasis and Anthropic’s R&D leadership stats.
Who feels it
- Lab security
- Employee ChatGPT/Codex privilege models need the same scrutiny as production APIs after a bounty path into GitHub orgs.
- AI researchers
- Anthropic’s 26% Claude-led R&D figure becomes a benchmark others will be asked to match or explain.
- Governments
- Cyber capability and recursive improvement land in the same week’s evidence pile for access and export debates.
What to watch
- Whether OpenAI publishes a fuller postmortem on the Discourse chain.
- Updated Anthropic (and peer) metrics on AI-led R&D share.
- New temporary access restrictions on cyber-oriented model builds.
Also covering this
AI · Sep 18, 2026
Researchers used Anthropic’s Claude to hack into OpenAI