DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Claude Used to Breach OpenAI Employee Account via Forum Flaw

Forensic Summary

Security researchers from Hacktron AI leveraged Anthropic's Claude to compromise an OpenAI employee's ChatGPT account through a vulnerability in OpenAI's Discourse-hosted community forum, gaining access to internal GitHub repositories. The attack chain — forum misconfiguration to internal SSO to privileged account — demonstrates how AI tooling can accelerate offensive security work against AI infrastructure. The incident also coincides with Anthropic disclosing that AI now leads 26% of its own R&D, raising broader concerns about recursive capability growth outpacing security controls.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/claude-used-to-breach-openai-employee-account-via-forum-flaw/

Top comments (0)