Researchers say Claude-assisted hackers accessed OpenAI employee accounts and internal code
Researchers say attackers chained vulnerabilities to compromise multiple OpenAI employee ChatGPT accounts and access internal repositories. The reported access could have exposed connected services, but the material does not establish broader customer impact.
What this could mean for you
Organizations using connected coding or collaboration services may need to review credentials and integrations.
Compromised employee accounts can provide an attacker with access to linked services and repositories.
Reported basis: [1][4] · The possible effect is interpretation.
Depends on: The reported account compromise must be confirmed and the relevant integrations must have been reachable.
Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.
For your country
Choose a country to check how this event could affect you.
What changes the outlook
Risk increases if…
Evidence that production systems, customer data or additional connected services were accessed.
Confirmation that compromised credentials remained valid after the reported intrusion.
Pressure eases if…
Independent confirmation that access was limited to a test repository and affected credentials were promptly revoked.
The details behind the risk
Open a detail to see which references were used. The source list includes available excerpts and links to the original articles.
Hacktron says attackers chained a heap-overflow vulnerability with an SSO misconfiguration to compromise multiple OpenAI employees’ ChatGPT accounts on July 25, 2026. [1]
References for this detail (1)
- Hacking OpenAIhacktron.ai · Sep 18, 2026, 4:02 AM UTC
Hacktron says the attackers used an employee’s Codex account to open pull request 1186742 in OpenAI’s internal repository as proof of access. [1]
References for this detail (1)
- Hacking OpenAIhacktron.ai · Sep 18, 2026, 4:02 AM UTC
Fortune’s headline identifies three people using Anthropic’s Claude as having hacked into OpenAI and accessed source code for a $6,500 reward. [2]
References for this detail (1)
- 3 guys using Anthropic's Claude hacked into OpenAI and accessed its source code for $6,500 rewardfortune.com · Sep 18, 2026, 12:17 PM UTC
Business Today’s headline says Anthropic’s AI security tool accessed OpenAI systems and employee credentials. [4]
References for this detail (1)
- Anthropic's AI security tool hacked OpenAI systems and accessed employee credentials: Here's what happenedbusinesstoday.in · Sep 18, 2026, 7:46 AM UTC
Context from the sources
Hacktron says the affected accounts could have provided access to services connected to ChatGPT and Codex, including other connectors, though the excerpt does not establish that sensitive data was taken. [1]
Explore the reporting
4 source links · 4 domains
These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.
Publication timeline
Oldest to newest among the references used here. These are publication times, not a chronology of the incident. A later article may repeat earlier information.
- [1] Hacking OpenAIhacktron.aiReferenced for: detail 1, detail 2
- [4] Anthropic's AI security tool hacked OpenAI systems and accessed employee credentials: Here's what happenedbusinesstoday.inReferenced for: detail 4
- [3] OpenAI 'ethically hacked' with help of Anthropic's Claude chatbotaol.co.uk
- [2] 3 guys using Anthropic's Claude hacked into OpenAI and accessed its source code for $6,500 rewardfortune.comReferenced for: detail 3
Still unclear
Whether OpenAI confirmed the incident and which accounts, repositories or connectors were actually accessed.
Whether any customer data, secrets or production systems were accessed or changed.
Market implications
Market impact
Sources (4)
References for the reported details. Separate links do not necessarily mean independent confirmation.
Available excerpt
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’…A short excerpt from our source record; open the original for the full article.
AI-assisted analysis · Sep 18, 2026, 12:27 PM UTC. Based on linked headlines and available excerpts. Methodology · Report an error.