An independent security research team used Anthropic's Claude software to breach a ChatGPT account belonging to an OpenAI employee and access an internal code system linked to the account, The Wall Street Journal reported. According to ChainCatcher, the researchers first used Claude to analyze a Discourse vulnerability used by OpenAI's developer community and generate working attack code, then obtained an authentication token and exploited a permissions configuration issue to enter the employee's ChatGPT account.
They also gained limited read access to some private GitHub repositories and the ability to submit suggested code changes.