SAN FRANCISCO — Cybersecurity researchers who broke into ChatGPT maker OpenAI earlier this summer say the artificial intelligence industry is unprepared for the security risks created by the growing power of its own technology.
Researchers from computer security start-up Hacktron got inside the company’s systems with help from the Claude chatbot made by OpenAI’s primary rival, Anthropic. After first targeting a public-facing messaging board they were able to access OpenAI’s private systems, including some of the AI company’s internal code, according to posts on X late Thursday by Hacktron describing the campaign.
OpenAI patched the problem and paid the hackers $6,500 for reporting the vulnerability. But the episode, along with incidents in which AI models accessed the internet undetected and attacked other companies, has drawn criticism from cybersecurity experts. They warn that the effort deployed by AI developers to protect their systems doesn’t match the immense power they claim their technology to have.
Mohan Pedhapati, one of the Hacktron researchers who broke into OpenAI, said the company’s use of conventional business software such as Slack, consumer-grade internet browsers and other apps that are accessible through the public internet, makes it vulnerable to a potential attack.
“If the people building these systems truly believe they are powerful enough to create nuclear-level risks, and they are talking about slowing down because of those risks, why is that work … done through ordinary SAAS products,” Pedhapati said early on Saturday in a post on X, using an industry term for cloud software.
OpenAI chief executive Sam Altman recently joined calls from other leaders in the field to slow the pace of AI development, out of concern that its capabilities are outstripping the industry’s ability to control the technology.
“We thank the researchers for contacting us and sharing their findings,” an OpenAI spokesperson said in a statement, which also said the company had tightened its security measures. (The Washington Post has a content partnership with OpenAI.)
Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University, said the ability of a small team of researchers to carry out a hack — at what they said was the cost of $3,000 paid for using Anthropic’s systems — should be considered a “warning shot.”
“If three responsible researchers armed with commercial AI tools could achieve this level of access in days, we have to assume well-resourced foreign intelligence services are pursuing the same targets continuously and certainly never tipping off the target about what they did and how,” Cilluffo said.
National security experts have long warned that American AI companies should expect to be targeted by hackers backed by foreign governments eager to cut into the United States’ lead in the technology. China has a history of seeking to steal U.S. technological secrets.
Calls for an AI slowdown have prompted lawmakers in both major parties to say the industry should be subject to more government oversight. President Donald Trump has firmly rejected such proposals, saying the industry must race forward to stay ahead of China.
The Hacktron breach of OpenAI, which used the security prowess of Anthropic’s chatbot Claude, comes after months of debate in the tech industry and Trump administration about how to respond to the growing power of AI models to identify security holes in software. Although OpenAI and Anthropic have restricted who can access the full cybersecurity skills of their chatbots, Chinese firms release free AI models that now have potent hacking capabilities available to anyone.
In July, OpenAI said some of its own AI agents had broken out of the company’s computer systems during internal tests, accessed the public internet and hacked into another AI company.
The incident triggered criticism from some cybersecurity experts, who said the company could have done more to make sure its AI couldn’t break out of its networks. OpenAI hired outside AI researchers to study why its agents escaped, but the investigation did not include a traditional independent cybersecurity postmortem.
The Hacktron hack of OpenAI happened around the same time as the incident involving the AI agents. Soon after, OpenAI redirected a substantial amount of engineering resources toward improving its security, OpenAI President Greg Brockman said in a podcast interview with venture firm Andreessen Horowitz released this week.
“We took 25 percent of our production engineers and said, ‘Sorry, all your projects are on hold. You are now defending,’” Brockman said. “We found a number of serious issues, and we fixed them.”
Hacktron’s researchers criticized how OpenAI responded when they notified the company they had found a way into their systems.
Like many major companies, OpenAI openly encourages security researchers to report vulnerabilities. Fabian Faessler, Hacktron’s head of agent engineering, said in a post on X early on Saturday that OpenAI’s chief information security officer, Dane Stuckey, had called the researchers unprofessional and that Faessler had expected a more welcoming response from the company.
Dan Wallach, an AI security resident at the research organization Rand, said OpenAI was fortunate that the vulnerability was discovered by researchers who came forward and shared what they found.
“As a general rule it’s not polite to do what they did, but I would think that OpenAI should be pleased that the attacker was nice enough to tell them,” Wallach said.
OpenAI’s Stuckey reached out to apologize after Faessler posted his X thread, Faessler said in a later post.
The post Hackers who broke into OpenAI warn the AI industry has a security problem appeared first on Washington Post.




