Cybersecurity3 mins read

Hacktron Used Claude to Flag OpenAI Vulnerabilities and Win a $6,500 Bounty

Business Insider reports that San Francisco-based AI cybersecurity startup Hacktron used Claude in authorized security research to exploit vulnerabilities tied to OpenAI accounts, then disclosed the issue and received a $6,500 bounty.

What Hacktron Found

Hacktron, a San Francisco-based AI cybersecurity startup, discovered gaps in OpenAI’s infrastructure in July, according to Business Insider. The reported vulnerability involved OpenAI’s community help forum and could have put ChatGPT and Codex accounts at risk for users or employees logging in there.

The startup later said it received a $6,500 bounty for the discovery. Hacktron was launched less than a year ago and has fewer than 10 employees.

How Claude Was Used in the Research

Hacktron tried to exploit the vulnerability using Claude. Zayne Zhang, Hacktron’s cofounder and CEO, told Business Insider the company had access to Anthropic’s Cyber Verification Program, which relaxed certain cyber restrictions on Claude for authorized security research.

The team managed to hack into an OpenAI employee’s account and prompt the employee’s Codex account to suggest changes in OpenAI’s internal code repository. Hacktron said it stopped there, did not access internal code, and reported the issue to OpenAI.

OpenAI’s Response

An OpenAI spokesperson told Business Insider: “We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”

Representatives for Anthropic did not respond to Business Insider’s request for comment. The episode highlights how authorized AI-assisted security testing is becoming more relevant as frontier AI systems are deployed across sensitive workflows.

Why This Matters for AI Security

Zhang told Business Insider that AI safety and cybersecurity are converging, and that more cybersecurity experts in the conversation is good for the industry. The incident comes as AI security has become a major tech concern.

Business Insider noted that OpenAI, Anthropic, and Meta have disclosed rogue actions by their agents during testing in recent months. The practical takeaway: companies building or using AI agents need tighter account permissions, faster token revocation, and careful rules for authorized security research.

Discover More

    Google Gemini logo with cybersecurity-themed illustration
    Gemini Test Breakout

    Gemini reportedly reached real company systems during a flawed security test.

    Google GeminiAI Security
    A macro close-up photograph shows the Google Gemini AI app icon
    Gemini’s AI Hacking Test

    Gemini accessed three companies’ protected systems during cybersecurity testing, according to TechCrunch.

    AICybersecurity
    DNA imagery used for TechCrunch article on Anthropic operating a biology lab
    Anthropic’s Biology Lab

    Anthropic is running a wet biology lab while positioning AI for life sciences research and warning about AI risks.

    AnthropicAI
    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping