A group of US cybersecurity researchers has said it carried out an "ethical" hack of OpenAI systems with assistance from Anthropic's Claude chatbot, compromising a number of OpenAI employees' ChatGPT accounts and accessing software caches, according to the researchers.
How the test unfolded
The team, which operates from a US-based startup, said the campaign began by taking over several individual ChatGPT accounts belonging to OpenAI staff. That initial compromise, they said, started a process that allowed them to reach a target's software cache and opened the possibility of further access inside the environment.
Scope and intent
The researchers described the exercise as an ethical or white-hat test intended to probe security weaknesses. They warned that the "scope of what we could theoretically access was huge," a phrase they used to characterise how much could be reached once the account-level foothold was established.
A broader context of concern
The incident is being reported as the latest example of security questions surrounding OpenAI's systems. While the researchers emphasised their testing motives, the account-level compromises and the potential for broader access are likely to deepen scrutiny of the company’s security posture.
Implications and next steps
The researchers said their work was aimed at highlighting vulnerabilities rather than exploiting them for malicious ends. The revelation underscores the challenges AI companies face as chatbots and associated accounts become integral to development workflows and may prompt renewed focus on account protections, monitoring and responsible disclosure practices.