Quoted claim
Viral shorthand after Hacktron's post: Claude hacked OpenAI. The phrase treats Anthropic's model as the actor that breached OpenAI.
Where made
Primary: Hacktron AI, "Hacking OpenAI", 13 September 2026. The authors describe using Claude Opus 4.8 and later Opus 5 sessions to help inspect Discourse's libheif packaging, develop memory-corruption reliability, and adapt to Discourse's environment. Humans directed the research, filed Bugcrowd and HackerOne reports, and stopped testing after a harmless Codex PR proof.
OpenAI's bounty comment, as quoted by Hacktron, scopes the $6,500 award to the OpenAI-side SSO finding. Discourse published GHSA-vhm9-85gw-x335 for RCE via malformed HEIF through the image-upload path.
Supporting number / method
Method: name the actor and the vulnerability owners.
- Actor: Hacktron researchers (named). Claude models were assistive tools inside that research workflow.
- Forum RCE owner: Discourse / upstream
libheifpackaging in the Docker image (GHSA). - Account-takeover bridge owner: OpenAI SSO identity flaw (Hacktron's framing; bounty scoped here).
- Anthropic: model provider used by the researchers. Not pleaded as the party that compromised OpenAI systems.
Hacktron also states the work was not fully autonomous. Skilled human guidance remained important even as model capability compressed timelines.
What would have to be true
For "Claude hacked OpenAI" to be accurate, the public record would need Claude operating as an autonomous agent that selected OpenAI as a target and executed the intrusion under Anthropic deployment, or an official finding that Claude was the attacking party. A human-led bounty write-up that used Claude as a coding assistant does not meet that bar.
Verdict
unsupported as a claim that Claude (the Anthropic product) hacked OpenAI.
supported that researchers used Claude models while disclosing a Discourse-plus-SSO chain that reached ChatGPT/Codex, and that OpenAI paid for the SSO-side issue.
Language we will use instead
We say Hacktron used Claude models while chaining a Discourse image-upload RCE to an OpenAI SSO flaw. We do not say Claude hacked OpenAI.
