Newsclip — Social News Discovery

Business

The Race for AI Security: When Rivals Become Threats

September 22, 2026
  • #Aisecurity
  • #Openai
  • #Anthropic
  • #Cybersecurity
  • #Artificialintelligence
  • #Techvulnerabilities
  • #Nationalsecurity
2 views•0 comments
The Race for AI Security: When Rivals Become Threats

How a Small Team Hacked One of Tech's Giants

When Mohan Pedhapati and his colleagues at Hacktron took on OpenAI, they didn't rely on traditional hacking methods. Instead, they used another AI model — specifically, Anthropic's Claude — to find a vulnerability in a third-party service that OpenAI depends on.

"We are the good guys," Pedhapati told me, emphasizing his team's ethical approach. "We were trying to help OpenAI by showing them where they were weak."

What makes this story more alarming than typical cybersecurity news is that it wasn't a sophisticated threat actor with deep resources. It was a small team of researchers — and yet, within days, they had penetrated systems that are supposed to be the gold standard in digital safety.

AI as a Force Multiplier

Pedhapati described modern AI models as 'force multipliers' — tools that amplify both the power and reach of cyberattacks. "As the models progress, they become very capable in cyber," he said. His team's hack took less than three days — something that would have taken months without these advanced tools.

But this speed comes with a cost: the rapid development of AI systems outpaces our ability to secure them. In the case of OpenAI, even though it has an established bug bounty program and offers rewards for ethical hackers, the very nature of how quickly models evolve makes it nearly impossible to stay ahead.

The Hidden Chain of Risk

One key insight from the Hacktron report is that modern tech companies aren't just vulnerable in their own code. They are exposed through a network of dependencies — third-party services and platforms like Discourse, used by OpenAI's community forum.

"You don't need to find a vulnerability in OpenAI source code itself," Pedhapati explained. "You can go one step down." This cascading effect means that even if a company like OpenAI builds robust internal defenses, it can still be compromised via an overlooked service provider.

This revelation has profound implications for all of us who depend on AI systems daily — from developers and businesses to everyday users. It's a reminder that when one part of the tech ecosystem is weak, everyone suffers.

OpenAI's Response

After being notified by Hacktron, OpenAI responded quickly. They patched the issue by updating access tokens and revoking compromised sessions. But this incident raises a bigger question: are these measures enough?

As AI continues to evolve at breakneck speed, the industry is struggling to maintain security in lockstep with innovation. We're seeing the early signs of what could become a systemic problem — not just within individual companies, but across the entire AI landscape.

The Bigger Picture: AI's National Security Implications

This isn't just a cybersecurity issue anymore. As Nicholas Leiserson, a cybersecurity policy expert at the Institute for Security and Technology, points out, powerful AI models are now considered national security assets — and they're also targets.

"I think unquestionably that the labs' technology is national security relevant," he said. If a small Indian firm can breach OpenAI in days, imagine what a nation-state might do with similar tools. The stakes have never been higher.

This isn't about one company's shortcomings; it's about how we govern and protect some of the most powerful technologies ever created.

Why This Matters for Everyone

When we talk about AI safety, many people think about misaligned objectives or unintended consequences. But this case shows a more immediate threat — that AI itself can be weaponized by those who know how to use it effectively. Whether through cyberattacks, stolen model weights, or unauthorized access, the tools that empower AI developers can also empower adversaries.

It's crucial that we begin thinking not only about protecting these systems but also about making them more resilient against such attacks from within and without. We need frameworks that ensure AI development is both rapid and responsible — balancing innovation with accountability.

The Path Forward

The response from the AI community so far has been mixed. While some leaders, like Anthropic's Dario Amodei, have acknowledged the risks, others continue to push for speed over safety. This tension is central to how we shape the future of AI.

What's clear is that we cannot afford to let our guard down. The systems we build today will define the digital world tomorrow — and if they're not built with security in mind, we may find ourselves at the mercy of those who can break in.

Conclusion: The Need for Accountability

As I reflect on this hack, I'm struck by how much it reveals about our current state of AI development. It's not just a technical failure — it's a systemic one. We must ask ourselves: are we building systems that can keep up with the threats they create? And more importantly, who is responsible for ensuring those safeguards exist?

What we're seeing here isn't an isolated incident — it's a wake-up call for all of us involved in shaping the future of AI. The race to build smarter machines must include a commitment to keeping them safe.

Key Facts

  • Primary hackers: Mohan Pedhapati and colleagues from Hacktron
  • Target company: OpenAI
  • Rival AI model used: Anthropic's Claude models
  • Vulnerability method: Exploiting third-party service Discourse
  • Hack duration: Less than three days
  • Affected systems: ChatGPT and Codex accounts
  • Security response: OpenAI patched by updating access tokens
  • Hacktron's motivation: Ethical hacking to help OpenAI identify vulnerabilities

Background

A cybersecurity team from India, Hacktron, used Anthropic's AI models to breach OpenAI's systems, revealing critical security vulnerabilities in one of the tech industry's most advanced platforms. The hack was executed through a third-party service that OpenAI depends on, demonstrating how interconnected systems create cascading risks. This incident occurred during a period when AI development is advancing rapidly, outpacing security measures and creating new challenges for cybersecurity professionals.

Quick Answers

Who hacked OpenAI using Anthropic's AI?
Mohan Pedhapati and colleagues from Hacktron hacked OpenAI using Anthropic's Claude models.
What AI model was used in the hack?
Anthropic's Claude Opus 4.8 and Claude Opus 5 were used in the hack.
When did the OpenAI hack occur?
The hack occurred in late July 2026, according to the article.
What was the purpose of the hack?
Hacktron conducted the hack to help OpenAI by identifying security vulnerabilities.
How long did it take to complete the hack?
The entire hack took less than three days, according to Hacktron's report.
What systems were compromised?
ChatGPT and Codex accounts of OpenAI users were compromised through the hack.
Did OpenAI respond to the hack?
Yes, OpenAI responded by patching the issue through updating access tokens and revoking compromised sessions.
What was Hacktron's approach?
Hacktron used Claude models as 'force multipliers' to amplify their hacking capabilities and speed up the process.

Frequently Asked Questions

How did Hacktron access OpenAI accounts?

Hacktron accessed OpenAI accounts by exploiting a vulnerability in Discourse, a third-party service used for OpenAI's community forum.

What made this hack different from typical cybersecurity breaches?

This hack was different because it was performed by a small team of researchers using advanced AI models rather than traditional hacking methods.

How did Claude help in the hacking process?

Claude helped by allowing Hacktron to find vulnerabilities much faster than would be possible manually, with Pedhapati saying it would have taken months without these tools.

What was the response from OpenAI?

OpenAI responded by patching the issue through updating access tokens and revoking compromised sessions after being notified by Hacktron.

Why is this hack significant for AI security?

This hack is significant because it demonstrates how quickly advanced AI models can be used to breach even sophisticated systems, revealing systemic vulnerabilities in the tech industry.

What did Mohan Pedhapati say about AI's impact on hacking?

Pedhapati described each new AI model as 'a force multiplier' that empowers hacking and noted that as models progress, they become very capable in cyber.

Source reference: https://www.cbsnews.com/news/openai-hack-anthropic-claude-vulnerabilities/

Comments

Sign in to leave a comment

Sign In

Loading comments...

More from Business