What happens when artificial intelligence is used to attack another AI company ?
A striking cybersecurity incident involving OpenAI and Anthropic has highlighted the growing power and potential risks of AI-assisted cyber operations. Researchers from cybersecurity company Hacktron AI reportedly used Anthropic’s Claude as part of an authorized security test to identify vulnerabilities in OpenAI’s systems.
During the exercise, the researchers were able to gain access to multiple employee ChatGPT and Codex accounts and reach parts of OpenAI’s internal GitHub environment. The researchers subsequently reported the vulnerabilities to OpenAI, allowing the company to investigate and fix the security issues.
OpenAI also reportedly paid the three Hacktron researchers a $6,500 bug bounty under its vulnerability disclosure program. The incident is significant because it demonstrates how an AI model designed to assist cybersecurity professionals can potentially automate and accelerate complex security testing and attack techniques. Importantly, this was a controlled and authorized security exercise, rather than an ordinary criminal cyberattack.

The episode has nevertheless intensified wider discussions about the security of increasingly powerful AI systems and what could happen if similar capabilities were used by malicious actors without authorization.
It also comes amid growing evidence that AI agents are becoming capable of carrying out increasingly complex tasks with limited human intervention, raising fresh questions about how companies can secure AI-powered systems before those capabilities are misused.
AI is becoming more powerful every day but the race to build smarter machines is now also becoming a race to secure them.


