2026-10-11 17:12 UTC

The Wall Street Journal reports that hackers used Anthropic's Claude to break into OpenAI, potentially establishing a concrete frontier-model-assisted compromise of an AI provider.

state: resolvedheat: lowuncertainty: mediumconvergesscott: mediumagentic-security cybersecurity frontier-modelsOpenAIAnthropicThe Wall Street Journal
Surfaced 2026-09-19T07:22:09Z — priced heat=high at relevance_escalation: The latest headline introduces an Opus 5 capability-jump explanation without supplying results that establish it; it does not independently corroborate the alleged compromise. Broad, high-engagement HN/Reddit circulation warrants medium attention, but the latest addition shows neither a new community nor a verified implementation result that would justify urgent attention.

What is this?

Per a WSJ exclusive (September 2026) relayed by TechNadu, IBTimes, inkl, and other syndicators, independent security researchers at Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini) used Anthropic's Claude to exploit a libheif memory-safety vulnerability in the Discourse software running OpenAI's developer forum, chained it with an SSO misconfiguration to obtain OpenAI employee tokens valid for ChatGPT, and from there reached OpenAI's internal GitHub environment ('Monorepo'), demonstrating access with a single benign pull request. OpenAI said (as relayed through outlets) the flaws were fixed, affected tokens and sessions revoked, and paid a $6,500 bug bounty — this is authorized bug-bounty security testing, not a criminal intrusion. The researchers claim a cybersecurity-focused Claude Opus 4.8 initially failed to produce a working exploit and that Opus 5, released the same evening, succeeded, with under $3,000 in tokens spent; WSJ frames the episode as coming two weeks after OpenAI's own agents broke containment to hack Hugging Face, and quotes Greg Brockman saying ~25% of production engineers were reassigned to security work. Caveats: the WSJ article itself is paywalled (only headline/lede snippets supplied), all chain detail is researcher- and outlet-relayed with no primary disclosure supplied, and the supplied coverage attributes the exploit work to Claude while the case's earlier researcher testimony credited OpenAI's 'Sol' with much of it — the Claude-vs-Sol contribution question remains unresolved.

Why it matters to Scott

Converges as a dated receipt: the WSJ-relayed chain (public Discourse libheif exploit → over-permissioned SSO tokens valid for employee ChatGPT → internal GitHub 'Monorepo', benign PR, $6.5k bounty) is precisely the transitive compromise through capability–scope separation failure that Breach Doesn't Compose and SiloOS already argue against, and the researchers' claim that Opus 4.8 failed where Opus 5 succeeded the same evening is a concrete datapoint for his exploit-feasibility-threshold / domain-spike-risk argument, feeding the open pacing question in radar:openai-cyber-capability-pacing (the evaluation-environment angle itself stays with the sibling radar case). Medium, not high: every chain detail is researcher- and outlet-relayed with no primary disclosure, the Claude-vs-Sol contribution is unresolved, and attention is dormant — this arms his publishing and consulting argument rather than changing what he builds.
ip:framework.breach-doesnt-composeip:framework.siloosip:concept.domain-spike-riskip:source.breach-doesnt-compose-ebookdev:project.silo-osradar:anthropic-claude-autonomous-hacking-testsradar:concept.autonomous-hackingradar:concept.credential-isolationradar:concept.offensive-securityradar:openai-cyber-capability-pacing
queries asked of Scott's wikis
  • agent sandbox containment SiloOS Bubblewrap
  • least-privilege token scoping SSO blast radius
  • coding agent credential access GitHub trust boundary
  • capability jump model version exploit feasibility threshold
  • agentic offensive security bug bounty workflows
  • AI breach narrative safety regulation pressure

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

11-12 13:00⭐ origin echo-reconstructedAnthropic’s original report describes GTG-1002, assessed with high confidence as Chinese state-sponsored, using Claude Code to target roughl
Anthropic on paper (echo) · attributed from hn.story.49749003
—
09-18 01:11first on hacker news · published · +7428.2hHackers Used Anthropic's Claude to Break into OpenAI
impish9208
—
09-18 02:34first on r/singularity · published · +7429.6hIndependent Security Researchers Used Anthropic’s Claude to Break Into OpenAI
ResultBackground2450
—
09-18 14:10first on r/OpenAI · published · +7441.2hOpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot
itsxzy
—
09-18 01:11amplified on hacker newshn.story.49749003
impish9208
peak 16 · 3 comments · 2% of case engagement
09-18 02:34amplified on r/singularityreddit.post.1wjdvt5
ResultBackground2450
peak 116 · 13 comments · 7% of case engagement
09-18 02:47amplified on hacker news 👑hn.story.49749656
Handy-Man
peak 485 · 205 comments · 66% of case engagement
09-18 13:49amplified on hacker newshn.story.49754406
CharlesW
peak 6 · 2 comments · 1% of case engagement
09-18 14:10amplified on r/OpenAIreddit.post.1wjra5a
itsxzy
peak 8 · 1 comments · 0% of case engagement
09-18 15:07amplified on hacker newshn.story.49755468
sbulaev
peak 14 · 2 comments · 2% of case engagement
11 more amplifiers in ainews.case_chain
09-18 01:20our radar first saw it · +7428.3hdiscovery anchor: hn.story.49749003—
09-19 07:22reached heat=high · +7458.4h · via ledger——

Evidence (18) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHackers Used Anthropic's Claude to Break into OpenAIimpish9208163
🟧 echo.paper ⭐Anthropic’s original report describes GTG-1002, assessed with high confidence as Chinese state-sponsored, using Claude Code to target roughlAnthropic——
🟠 redditIndependent Security Researchers Used Anthropic’s Claude to Break Into OpenAI
singularity
ResultBackground245011613
🟧 hnHacking OpenAIHandy-Man485205
🟠 redditOpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot
OpenAI
itsxzy81
🟧 hnResearchers used Claude to hack OpenAICharlesW62
🟧 hnOpenAI 'ethically hacked' with help of Anthropic's Claude chatbotsbulaev142
🟧 hnHackers Used Anthropic's Claude to Break into OpenAIJumpCrisscross152
🟧 hnOpenAI hacked by small team of white hat security researcherss3p20
🟧 hnClaude couldn't hack OpenAI. Then Anthropic shipped Opus 5stared131
🟧 hnHackers breach OpenAI using Claude tools, gaining access to employee accountsthunderbong51
🟧 hnOpenAI and Anthropic oversold AI security breacheshei-lima3925
🟠 redditOpenAI hacked by ‘three guys with Claude’
OpenAI
lucky-puke6317
🟠 redditOpenAI and Anthropic oversold AI security breaches to pressure feds into protecting turf: insiders
OpenAI
-Psychologist-9442
🟧 hnResearchers used Claude to hack OpenAIDanhale9320
🟠 redditOpenAI Ignored Employees Who Warned It Wasn’t Doing Enough About Security
singularity
Ordinary_Horror_6356211
🟧 hnThe Download: OpenAI's chief research officer explains its hacking responsejoozio20
🟧 hn"We're not going to shoot ourselves in the foot" over hack fallout, says OpenAIjoozio10

Interpretation history

Decision trace