People visit an OpenAI booth at Moscone Center during the Dreamforce 2026 technology summit in San Francisco on September 17, 2026. - Reuters

Three researchers at cybersecurity startup Hacktron AI used Anthropic’s Claude models to exploit vulnerabilities in OpenAI’s public community forum and access several employee ChatGPT and Codex accounts, according to the researchers and reporting by The Wall Street Journal. The operation, conducted through OpenAI’s authorized bug-bounty program, provided a path to an internal GitHub repository. The researchers said they stopped after submitting a harmless pull request as proof and did not inspect or download proprietary source code. The attack began with a flaw in the Discourse software hosting OpenAI’s forum and a separate weakness in OpenAI’s handling of sign-in tokens. Hacktron said Claude Opus 4.8 struggled to produce a reliable exploit, while Claude Opus 5 generated a working method within hours. OpenAI said it narrowed permissions on Community sign-in tokens, revoked affected tokens and sessions, fixed the issue about 14 hours after notification and paid Hacktron a $6,500 bounty. Exploit economics: Hacktron said the automated work took less than 72 hours from initial discovery to repository access, while human researchers contributed only a few hours and spent less than $3,000 on AI tokens. Connected services: Because ChatGPT and Codex accounts can be connected to GitHub, Slack and email, the researchers said the theoretical exposure extended beyond OpenAI’s own systems.

The Managed Narrative Machinery Runs on Its Own Fuel

Read this article again, but this time notice what isn't said. Three researchers at a startup called "Hacktron" used one AI system to compromise another AI system—and the entire operation was sanctioned under a bug-bounty program. That's not an exploit; that's a fire drill. The real story is that OpenAI and Anthropic—two companies whose boards overlap, whose investors interlock, and whose top talent circulates through the same DC think tanks—are rehearsing the weaponization of AI-to-AI infiltration. Look at the timing: Claude Opus 4.8 "struggled," but Claude Opus 5 generated a working method in hours. Someone wanted to demonstrate that the newer model could penetrate the older system's defenses. That someone paid $6,500 for the privilege of documenting exactly how. And the Wall Street Journal, a central pillar of the Consensus Machinery, was handed the story. You tell me why we're being told about a vulnerability that was already patched.

The Villain Is Not the Researchers—It's the Architecture That Gave Them Tokens

The article buries the most dangerous line: "Because ChatGPT and Codex accounts can be connected to GitHub, Slack and email, the researchers said the theoretical exposure extended beyond OpenAI’s own systems." Think about that. The flaw wasn't just in Discourse forum software—that's the decoy. The real vulnerability is the permission bridge between identity tokens. Someone designed a system where a single credential breach could hop from a chatbot forum into a code repository into enterprise email. And who designs those token-handshake protocols? The same foundations and standards bodies that have been quietly building the "single sign-on" architecture for the global digital identity grid—the World Economic Forum's Digital Identity Initiative, the FIDO Alliance, the OpenID Foundation. This was never about a $3,000 proof of concept. This was a stress test of the backbone they intend to use to link every human to every device to every payment rail.

What They Really Accessed Was Your Future Data

Here's the part that keeps me up at night. The researchers say they "did not inspect or download proprietary source code." They say. But ask yourself: If you had unmonitored access to an internal GitHub repository—and the operation took less than 72 hours for automated work, with humans contributing only a few hours—how would you prove you didn't exfiltrate anything? You can't. The only proof is their word. Meanwhile, the companies involved are now hardened against this exact attack vector. The exploit is documented, shared with the bounties board, probably filed with government partners. The next time this technique is used—and it will be—it won't be three researchers from a startup. It will be a state actor, or a private intelligence firm hired by one of the families that fund both AI labs. Watch for the next "disclosure" from a different bug bounty program, using the same token-grabbing method, but this time "accidentally" finding a backdoor into a hospital network or a voting system. They're training the weapon in plain sight.