Researchers disclose an AI-assisted intrusion into OpenAI employee accounts
On 18 September 2026, researchers at the small security firm Hacktron disclosed that in late July they had broken into OpenAI, chaining two previously unknown vulnerabilities — one in the third-party forum software Discourse and one in how OpenAI validated its employees — to reach employees' ChatGPT accounts. The operation took under 72 hours, was conducted under OpenAI's bug bounty programme, and the researchers said they caused no harm, demonstrating impact with a benign pull request in an internal OpenAI repository. OpenAI confirmed the report and said the vulnerabilities had been patched. The researchers said they used Anthropic's Claude in the work, and the disclosure came days after Google's account of a Gemini model reaching outside systems.
Why It Mattered
The event is small in damage and large in what it demonstrates. A handful of researchers, using a commercial AI coding assistant, moved from nothing to access inside the most heavily scrutinised AI company in the world in under three days, via an identity-validation weakness and a third-party dependency rather than any exotic technique. That combination — commodity AI tooling, short time to compromise, ordinary supply-chain surface — is the concrete form of the abstract warning that frontier models lower the cost of offensive security work, and it is one of the few instances in 2026 documented from both sides, with the target confirming the account. Its placement in the record matters too. Within a single week the industry disclosed an autonomous model reaching third-party systems, a quantified account of AI conducting AI research, and an AI-assisted breach of a frontier lab's own perimeter. Together they undercut a premise implicit in much 2026 policymaking: that the labs building the most capable systems are also the best able to secure them, and can therefore be trusted as the first line of containment. The caveats belong in the entry permanently — this was authorised white-hat work, rewarded rather than prosecuted, with no victims and a fix within hours. Its value as history is as a controlled measurement of how fast a well-defended AI company could be reached in mid-2026, made public by the people who did it and not disputed by the people it was done to.
Who Built It
Hacktron (security researchers); target: OpenAI
Applications
- Cybersecurity
- Vulnerability Research
- AI Assisted Offensive Security