Published: · Region: Global · Category: cyber

Researchers breach OpenAI staff ChatGPT account via forum flaw, exposing internal tools in paid test

Cybersecurity researchers using Anthropic tools hacked an OpenAI employee’s ChatGPT account by exploiting a weakness in the company’s third‑party Discourse forum, gaining access to internal software details and GitHub code before OpenAI fixed the bugs and paid them $6,500 under its bug bounty programme.

Three cybersecurity researchers managed to get into an OpenAI employee’s ChatGPT account and access information about internal software tools and GitHub code, using a route that ran through the company’s community forum.

According to the Financial Times, the researchers, working as Hacktron AI, used tools from rival AI firm Anthropic to help exploit a flaw in OpenAI’s third‑party Discourse forum. Discourse is widely used to run online discussion communities; in this case, vulnerabilities in the forum setup allowed the team to escalate their access.

From the compromised forum environment, the researchers were able to breach the OpenAI staff member’s ChatGPT account. That account in turn exposed details about internal software and code repositories on GitHub, though there is no indication that model weights or customer data were taken.

The entire operation was carried out under OpenAI’s bug bounty programme, which pays external researchers to find and responsibly disclose security weaknesses. In this case, OpenAI said it fixed the vulnerabilities and paid the Hacktron AI team $6,500.

The incident shows how the security of high‑profile AI labs can hinge not only on their core systems but also on the community platforms, forums and other services connected to them. A weakness in a third‑party forum was enough to open a path into an internal staff account tied to development tools.

What will matter now is whether AI companies tighten security around these peripheral systems and how they balance open community engagement against the risk that attackers will look for similar weak spots. Any future disclosures of attacks that move from external forums or support tools into internal AI development environments will show whether this case remains a controlled warning or becomes a template for more serious breaches.

Sources