A bug-hunting independent security research team reportedly gains access to OpenAI’s internal code system by using Anthropic’s Claude, according to multiple reports. OpenAI pays the researchers a $6,500 bug bounty after the issue is disclosed, the outlets say.
The incident is framed by both sources as an example of how AI-enabled tools can be used in cybersecurity testing and potentially by malicious actors. While the reporting centers on the same event—researchers leveraging Claude to reach OpenAI infrastructure—the details emphasize different aspects: one outlet highlights the bug bounty and the broader trend of threats from automated AI agents, while the other focuses on the access gained and the implications for organizational security.
Across the coverage, the common thread is that the researchers’ actions expose vulnerabilities in systems that support code and development workflows, and that the disclosure triggers a formal response through the company’s bug bounty program.