VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

Anthropic's Claude models used to breach OpenAI's GitHub monorepo

Security researchers in an OpenAI bug bounty program used cybersecurity versions of Anthropic's Opus 4.8 and Opus 5 to access OpenAI's monorepo on GitHub.

Independent security researchers used Anthropic's Claude models to hack into OpenAI's internal code systems, accessing the company's monorepo on GitHub, according to reporting by the Wall Street Journal's Robert McMillan2.

The researchers, operating within an OpenAI bug bounty program, deployed cybersecurity-tuned versions of Opus 4.8 and Opus 5 to carry out the breach. The Wall Street Journal described the incident as exposing growing risks in automated cyber threats. The Financial Times separately confirmed the breach, reporting that Anthropic models were used to penetrate OpenAI's systems3.

The target was OpenAI's monorepo on GitHub, a centralized repository that typically houses a significant portion of an organization's codebase. The researchers were characterized as a bug-hunting independent security research team that gained access to OpenAI's internal code system.

ANALYSIS The use of one frontier AI lab's models to breach another frontier AI lab's infrastructure marks a concrete demonstration of AI-augmented offensive cybersecurity capabilities moving from theoretical risk to operational reality.

The breach occurred within the framework of an OpenAI bug bounty program.

ANALYSIS That the researchers operated under a bug bounty program rather than as hostile actors distinguishes this from a malicious intrusion, but the technical achievement — using AI models to identify and exploit vulnerabilities in a major AI company's infrastructure — carries the same security implications regardless of intent.

The incident was reported across multiple outlets, including the Wall Street Journal, the Financial Times, and social media channels1, with consistent core details: Anthropic's Claude models were the offensive tool, and OpenAI's monorepo was the target.

ANALYSIS The specific mention of "cybersecurity versions" of Opus 4.8 and Opus 5 suggests purpose-built or fine-tuned configurations of Anthropic's models oriented toward vulnerability discovery, a capability tier that has now been demonstrated against production infrastructure at a peer organization.