• Sources: Guardian report, HN discussion, second thread
  • Summary: The chain published on 2026-09-18 ran from a staff discussion forum hosted on the Discourse platform to employee ChatGPT accounts and then to a GitHub repository, and the researchers used Claude and GPT-5.6 in the work. The Guardian reports the researchers stressed they had access to, but did not download, the code from that GitHub repository, which bounds what the chain achieved. Authorization rests on the Guardian's reporting that Hacktron operated under OpenAI's ethical-hacker programme and on the 6,500 dollar bug-bounty payment, not on OpenAI's own words, since the Guardian quotes OpenAI only thanking the researchers for sharing their findings and noting it addressed the vulnerabilities. A Wall Street Journal item circulating under a headline saying hackers used Anthropic's Claude to break into OpenAI frames the same work as an intrusion, and it is the second thread linked above.
  • Why it matters: The authorized framing changes what the result demonstrates, from an attack on OpenAI to a paid test showing community forum software beside an identity boundary is production attack surface.

send feedback on this story