Report: Three Researchers Used Claude Opus 5 to Breach an OpenAI Employee's Codex Account
EthanJPerez · x · 2026-09-18
Per the WSJ, three researchers at Hacktron AI, operating under OpenAI's bug-bounty safe harbor, used Claude Opus 5 in late July to break into an OpenAI employee's Codex account, read the company's private GitHub monorepo, and open a pull request as proof of the intrusion. The incident highlights the growing capability of AI-driven attacks and the boundaries of AI security.
Related event: Researchers Used Claude to Breach OpenAI's Internal Codebase(22 posts)→
More from Safety
- Air-gapping is leakier than you think: LED exfil at 100 kbps and dozens of side channels — dioscuri · 2026-09-18
- NHTSA developing federal ADS performance standard as US preps for larger-scale Robotaxi rollouts — Scobleizer · 2026-09-18
- Models fill in blanks: a pre-execution gate that strips verdict authority from LLMs — Jay299792458 · 2026-09-18
- tszzl: Weight self-exfiltration can only be done at the lab, not via side channels — tszzl · 2026-09-18
- That viral "air-gapped data exfiltration" paper only read temperature over a 4cm gap — basedjensen · 2026-09-18
- New paper shows models can fingerprint and exploit inference engines like vLLM using output tokens alone — chaumian · 2026-09-18