A Tiny Security Firm Just Hacked OpenAI Using OpenAI’s Own AI — With Permission
Hacktron AI, a small security research outfit, compromised several OpenAI employees’ ChatGPT accounts in an authorized penetration test — and the tool that got them furthest in was OpenAI’s own model.

Here’s how it actually played out:
- → The researchers started with Anthropic’s Claude to work through an attack path involving an internal OpenAI staff discussion forum running on Discourse
- → From there, they reached employee accounts and pushed far enough to submit a harmless pull request against OpenAI’s own code on GitHub — proof-of-concept, not real damage
- → Hacktron said it could access OpenAI’s code but didn’t download any of it
- → As the attack progressed, the team leaned heavily on OpenAI’s own GPT-5.6 Sol model to carry it further
- → The work was reported through OpenAI’s official bug-bounty program, and OpenAI confirmed it has since fixed the vulnerabilities
- → Hacktron’s own assessment: AI compressed work that once needed a well-resourced team and months of effort into a matter of days
Here’s what makes this different from a normal pentest writeup: the AI systems involved weren’t just tools sitting on the sidelines. They were simultaneously the target (OpenAI’s infrastructure), the defense (the same models are used to secure that infrastructure), and the offense (the models that found and exploited the path in). That’s an unusual loop for any industry to be operating inside — the company being attacked, the company whose model did the attacking, and the company whose model got exploited were three different labs, and two of them were rivals.
For security teams everywhere, the real lesson isn’t “OpenAI got hacked.” It’s that reconnaissance, exploit development, and attack-chain construction — the slow, expensive parts of a real intrusion — can now be automated by tools that are one API call away from anyone, ethical researcher or not. The skill floor for sophisticated attacks just dropped, and it dropped industry-wide, not just for the lab whose name is in the headline.
If a small team with off-the-shelf AI models can compress months of offensive security work into days on a company as security-conscious as OpenAI, what does that mean for organizations with far less mature defenses?
#Cybersecurity #AI #OpenAI #Anthropic #InfoSec #AISecurity #TechNews
Sandeep Raiza — Content Writer, Website Designer, SEO Strategist, and WordPress Expert AI specialist delivering impactful digital solutions that drive business growth.Combining creative storytelling with technical expertise.





