Three researchers at security firm Hacktron used Anthropic’s Claude Opus 5 to identify and chain together two separate vulnerabilities, ultimately taking control of the ChatGPT and Codex accounts belonging to several OpenAI employees. The research chain reportedly extended far enough to grant access to an internal OpenAI code repository.

According to the disclosure, the attack path began with a bug in the software powering OpenAI’s public help forum. Researchers then pivoted through a separate weakness in OpenAI’s own authentication and login infrastructure, combining the two flaws to escalate access from a public-facing surface into internal employee accounts.

AI as a Vulnerability Research Accelerator

The case is notable less for the individual bugs involved and more for the role Claude Opus 5 played in the process. The researchers used the model to help identify and connect the two flaws into a working exploit chain, illustrating how large language models are increasingly being used as force multipliers in offensive security research, not just for writing code or summarizing reports, but for actively assisting in vulnerability discovery and chaining logic.

The activity was conducted as authorized security research rather than a malicious intrusion. It has not been disclosed whether OpenAI has issued a bug bounty payout, patched the underlying flaws, or confirmed the specific components affected.

Why This Matters

The incident underscores a growing trend that security teams should watch closely: individual vulnerabilities that might be considered low or moderate severity in isolation can become high-impact when chained, and increasingly capable AI models are lowering the skill and time barrier required to find and connect those chains.

  • Help desk and support forum software often runs on older or third-party codebases and can be an overlooked entry point into corporate identity systems.
  • Authentication and single sign-on weaknesses remain a common pivot point for escalating from low-privilege footholds to sensitive internal access.
  • Organizations building or deploying AI coding and reasoning assistants internally should assume similar tools could be used against them by external researchers or attackers.

Security teams are advised to treat public-facing support and community platforms as part of their core attack surface, apply strict segmentation between those systems and internal authentication infrastructure, and monitor for anomalous account takeover patterns tied to employee credentials.