AAPL $339.75 +0.31% ▲ ACN $183.72 -1.29% ▼ ADBE $238.25 -4.32% ▼ ADEA $25.83 +1.14% ▲ ADIG $21.02 +0.48% ▲ ADP $269.64 -0.24% ▼ ADSK $219.62 +0.37% ▲ AEHR $100.60 +2.92% ▲ AEVA $15.41 +0.06% ▲ AGYS $100.37 +0.12% ▲ AI $10.85 +0.28% ▲ AIP $24.78 +3.25% ▲ ALAB $363.46 +6.01% ▲ ALKT $18.09 +0.44% ▲ ALNT $108.06 -1.18% ▼ AMBA $67.06 -3.13% ▼ AMBQ $71.05 -2.52% ▼ AMD $623.77 +0.61% ▲ AMPL $13.14 -2.16% ▼ AMZN $254.98 -1.61% ▼ ANET $205.19 -0.38% ▼ AOSL $28.28 +7.94% ▲ APLD $28.54 +0.76% ▲ APP $328.73 -0.26% ▼ APPN $36.90 -4.77% ▼ APPS $12.19 +0.74% ▲ ARM $333.20 +2.52% ▲ ARRY $3.96 -2.86% ▼ ARW $221.83 +1.25% ▲ ASML $1,747.90 +1.74% ▲ AAPL $339.75 +0.31% ▲ ACN $183.72 -1.29% ▼ ADBE $238.25 -4.32% ▼ ADEA $25.83 +1.14% ▲ ADIG $21.02 +0.48% ▲ ADP $269.64 -0.24% ▼ ADSK $219.62 +0.37% ▲ AEHR $100.60 +2.92% ▲ AEVA $15.41 +0.06% ▲ AGYS $100.37 +0.12% ▲ AI $10.85 +0.28% ▲ AIP $24.78 +3.25% ▲ ALAB $363.46 +6.01% ▲ ALKT $18.09 +0.44% ▲ ALNT $108.06 -1.18% ▼ AMBA $67.06 -3.13% ▼ AMBQ $71.05 -2.52% ▼ AMD $623.77 +0.61% ▲ AMPL $13.14 -2.16% ▼ AMZN $254.98 -1.61% ▼ ANET $205.19 -0.38% ▼ AOSL $28.28 +7.94% ▲ APLD $28.54 +0.76% ▲ APP $328.73 -0.26% ▼ APPN $36.90 -4.77% ▼ APPS $12.19 +0.74% ▲ ARM $333.20 +2.52% ▲ ARRY $3.96 -2.86% ▼ ARW $221.83 +1.25% ▲ ASML $1,747.90 +1.74% ▲

Independent researchers say Claude-powered effort breached OpenAI employee accounts in under three days

September 18, 2026 · by TPW Pipeline

Independent researchers say Claude-powered effort breached OpenAI employee accounts in under three days

A trio of independent security researchers reports that it managed to break into OpenAI employee accounts in less than 72 hours, using Anthropic’s Claude Opus 4.8 and Claude Opus 5 models to assist the operation, according to a report by the Wall Street Journal and coverage from The Verge.

The team, based at security firm Hacktron, said the intrusion granted access to OpenAI’s internal GitHub repository, known internally as “Monorepo.” Sources cited by the Wall Street Journal describe the repository as holding some of OpenAI’s most sensitive algorithmic material. The researchers stated they did not view internal source code, but sent a pull request from an employee’s Codex account as evidence of their access.

The entry point, per the researchers’ write-up, was Discourse, the third-party platform that hosts OpenAI’s community forum. The disclosure adds to a growing body of incidents showing how frontier AI systems can accelerate offensive security work, raising fresh questions about how major AI labs secure their own infrastructure and how they evaluate the dual-use potential of their flagship models. Neither OpenAI nor Anthropic has publicly detailed remediation steps in the immediate aftermath, though Hacktron has published information about affected versions and patches on its blog.

The episode lands amid continued investor focus on the security posture of AI companies, whose repositories and training pipelines are increasingly viewed as high-value targets. Broader technology-sector names with cybersecurity exposure remain under scrutiny as enterprises reassess identity and third-party vendor risk; Block, Inc. (XYZ), a software-infrastructure company in the Technology sector, traded at $77.03 on the day, up 0.17% from its prior close of $76.90, with a market capitalization of roughly $46.28 billion.

The full account of the operation, which The Verge has dubbed part of the “Heif Heist” reporting, is available in the publication’s extended coverage of the incident.

Source: original release

What to watch

  • Formal statements from OpenAI and Anthropic regarding the reported breach and any model-usage policy changes.
  • Details from Hacktron on which Claude versions were affected and what patches have been deployed.
  • Possible updates to Discourse’s security practices or OpenAI’s use of third-party forum hosting.
  • Upcoming earnings from major AI labs, where security disclosures may face analyst questions.

Stocks in this story