Skip to content

OpenAI

Disclosed Sep 17, 20268 days agoUnverified

Researchers used Claude to chain bugs and take over OpenAI employee ChatGPT accounts

A three-person team at Hacktron AI used Anthropic's Claude to chain two critical vulnerabilities that gave access to multiple OpenAI employee ChatGPT accounts and entry into company software, reporting it through OpenAI's bug bounty for a $6,500 award; OpenAI said the issues were resolved.

What is known

People affectedNot stated in the sources we have
DisclosedSep 17, 2026
AttackHacking
Data exposedCredentials and tokens, Prompts and chats, Internal documents
SectorAI · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 17

Other breaches at OpenAI

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about OpenAI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.