Three security researchers gained access to an OpenAI employee’s ChatGPT account and internal software information by exploiting the company’s community forum, according to a report carried by Ars Technica. The forum runs on the third-party Discourse platform, and the flaw enabled the team to move from that service into internal sign-on systems.
The compromised employee account could reach code held in OpenAI’s GitHub environment and suggest changes. The researchers, from the small security company Hacktron AI, used an Anthropic tool designed for security professionals during the work. They disclosed the flaws through OpenAI’s bug-bounty program and received $6,500. OpenAI said it had fixed the issues and thanked the team for reporting them; Anthropic declined to comment.
The episode demonstrates two distinct security pressures: AI tools can accelerate authorized vulnerability research, while links between external community software, employee identities and code systems can widen an organization’s attack path. The work was conducted as ethical testing rather than an attack by a hostile party. The report does not say the researchers changed production systems or that customer data was exposed. It does show how a weakness in a peripheral service can become serious when accounts inherit access to sensitive development resources.