Hacktron AI researchers used Claude to break into OpenAI’s internal code repository, and OpenAI paid them a $6,500 bounty

by | Sep 20, 2026 | Latest E-commerce News & Updates

Hacktron AI, a three-person security firm, used Claude to break into OpenAI’s internal code repository through a bug in Discourse, the software running its community forum, and OpenAI paid the team a $6,500 bounty, according to Robert McMillan at The Wall Street Journal. A cybersecurity-restricted version of Claude Opus 4.8 couldn’t produce working attack code on July 23, but Anthropic released Opus 5 that evening and the model had an exploit working the next day. That gave the researchers authentication tokens off the forum server, some belonging to OpenAI employees and valid on ChatGPT and GitHub, which let them read files in Monorepo, the repository behind OpenAI’s models though not the model weigh

Paul Drecksler is the founder and editor of Shopifreaks, covering the most important stories in e-commerce.

Companies: OpenAI

Never miss important e-commerce news

Our weekly newsletter is read religiously by 20,000+ e-commerce professionals.

Loading...