SDSignal Desk

Researchers used Claude to hack OpenAI

Sep 18, 2026, 6:30 AM · Ars Technica

Image: Ars Technica

Ars (via Financial Times) adds that Hacktron’s Claude-assisted break-in reached an employee ChatGPT account with GitHub code access—and lands as Anthropic says Claude now leads 26% of its R&D work, up from 1% in March.

Why it matters

Same bounty, sharper stakes: researchers used an Anthropic cyber tool to reach OpenAI internal software information and suggest code changes through an employee account.

OpenAI paid $6,500, fixed the issues, and thanked the researchers. The timing—weeks after OpenAI agents hacked Hugging Face—keeps security and recursive improvement in the same headline frame.

Anthropic’s parallel disclosure that Claude leads 26% of R&D (from 1% in March) makes the recursive self-improvement debate less theoretical while a rival’s model is proving it can crack lab defenses.

From the desk

We’re pairing the break-in with Anthropic’s R&D share number because they belong in one conversation.

FT/Ars emphasize what the employee account unlocked: private software information and suggested changes, with Codex wired to OpenAI’s GitHub organization. The entry remained Discourse on the community forum. Anthropic declined comment; OpenAI confirmed the fix.

Separately, Anthropic published that 26% of research and development work is now “led by” Claude—majority of tasks under human instruction and supervision—up from 1% in March. On 90% of tasks, AI still collaborates with a human. The company framed the data as helping the public see how close recursive self-improvement is. Models aren’t fully autonomous on the studied research yet. They are already doing most of the work on a rising share of tasks.

Useful AI that accelerates lab research is genuine progress. The harm if oversight lags: the same capability class that shortens exploit development also shortens the loop from model to next model. Temporary U.S. blocks on some Anthropic tools already showed how nervous governments are about cyber-capable releases. I’m watching whether recursive-R&D metrics and bug-bounty exploits force harder access gates—or just more press cycles.

Context

Ars Technica / Financial Times, September 18, 2026. Complements TechCrunch’s Discourse/libheif technical path with FT’s GitHub-access emphasis and Anthropic’s R&D leadership stats.

Who feels it

Lab security
Employee ChatGPT/Codex privilege models need the same scrutiny as production APIs after a bounty path into GitHub orgs.
AI researchers
Anthropic’s 26% Claude-led R&D figure becomes a benchmark others will be asked to match or explain.
Governments
Cyber capability and recursive improvement land in the same week’s evidence pile for access and export debates.

What to watch

  1. Whether OpenAI publishes a fuller postmortem on the Discourse chain.
  2. Updated Anthropic (and peer) metrics on AI-led R&D share.
  3. New temporary access restrictions on cyber-oriented model builds.

Read the original

Continue at the source.

Ars Technica

Companies: OpenAI, Anthropic

Also covering this