Three researchers breached OpenAI's internal monorepo in 72 hours using Claude

Under OpenAI's bug bounty safe harbor framework, three independent security researchers used Anthropic's Claude to break into OpenAI's internal systems in late July, reaching private code repositories and even submitting a PR — all in roughly 72 hours for under $3,000 in API tokens. The incident came to light after a Wall Street Journal report and the researchers' own post-mortem, underscoring how LLMs can dramatically amplify the efficiency of real-world attacks. OpenAI paid a $6,500 bounty, and no actual damage occurred.

Confirmed

Unconfirmed

Why it matters

2026-09-18 ~ 2026-09-18 · 17 related posts

Primary sources

1 near-duplicate retellings: Miles_Brundage