On July 23, 2026, the independent research team Hacktron AI announced they’d gained access to OpenAI’s internal infrastructure and a secret repository—using Anthropic’s Claude model. The incident happened during OpenAI’s official vulnerability disclosure program. After reporting the bug, OpenAI paid the team a $6,500 bounty.
What Happened
According to Hacktron AI, they used Claude to launch an attack as part of OpenAI’s bug bounty program. The move let them reach internal OpenAI resources, including a confidential repo. This was all above board—part of security testing under OpenAI’s established rules.
Details and Bounty
Once they’d found the vulnerability, the researchers reported it to OpenAI and got a $6,500 reward for their bug report. No further technical details were shared in this announcement.
Why It Matters
This case shows that large AI models aren’t just for defense—they can also help uncover weaknesses in corporate infrastructure during responsible disclosure programs. For the industry, it’s a wake-up call to regularly rethink testing and access controls, especially when AI tools are in the mix.
