WSJ: Three Attackers Plus Claude and Codex Stole OpenAI's Algorithmic Secrets, Not Weights

trevposts · x · 2026-09-18

A debate over the reported theft of OpenAI's algorithmic secrets: Sneha Revanur relays a WSJ report saying three individuals, using Claude and Codex, obtained only the "secret sauce" (OpenAI's algorithmic secrets) rather than the "crown jewels" (the model weights). She doubts Chinese threat actors haven't gotten further, arguing that racing faster only creates an illusion of a lead, and that serious frontier security would mean following through on export controls and pacing so labs make wiser speed-vs-security trade-offs.

The quoted post claims that on July 25 they "hacked OpenAI": two bugs let them take over ChatGPT/Codex accounts of OpenAI employees (plus some unaffiliated users) and reach connected services like Outlook, Slack and GitHub, proving it with a PR in OpenAI's internal codebase—all in under 72 hours.

Related event: Researchers use Claude to breach OpenAI's internal codebase(19 posts)→

Original post →

More from Safety

Safety channel →