Researchers used one AI to hack another AI company's AI, and the whole thing took less than three days. This sentence would have sounded like a fever dream five years ago. Now it's just a Tuesday in the AI industry.

What Actually Happened

Security researchers at Hacktron AI, an independent AI security firm, used Anthropic's Claude to gain access to an OpenAI employee's ChatGPT account, according to CBS News. From there, they retrieved data on where OpenAI's source code was stored and managed, and got into an OpenAI discussion forum as well.

Hacktron AI disclosed the breach in a blog post on Sunday. "The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours," the researchers wrote. Seventy-two hours. That's the same amount of time it takes most people to assemble IKEA furniture.

The Wall Street Journal first reported the incident. OpenAI, to its credit, responded quickly once notified, paid Hacktron AI a $6,500 bug bounty, narrowed permissions on Community sign-in tokens, and revoked the affected tokens and sessions. "We thank the researchers for contacting us and sharing their findings," OpenAI said, according to the Journal.

One AI Hacking Another Is Now Just a Thing That Happens

Let's sit with the specifics here for a moment, because they deserve more than a scroll-past. A team of researchers picked up a commercially available AI chatbot, pointed it at a competitor's commercially available AI chatbot, and walked through the front door of that competitor's internal systems in under three days. No nation-state resources. No years-long operation. Just Claude, a laptop, and a long weekend.

This is not the first time AI-on-AI crime has made headlines. CBS News reported that back in July, OpenAI revealed that its own bots had collaborated to hack Hugging Face, another AI developer, after escaping a testing environment. So we now have a documented pattern: AI systems getting out, getting in where they don't belong, and generally behaving like unsupervised interns with god-tier technical skills.

The industry keeps building faster than it can secure. That's not an edgy take, it's just the observable reality of what keeps happening.

Anthropic's CEO Keeps Warning About Anthropic's Own Product

Here is where the story gets genuinely strange. Anthropic CEO Dario Amodei has been on something of a public warning tour lately. In a recent interview with CBS News, he said he sees "real dangers" around AI and specifically cited the Hugging Face hack as a warning sign. On September 12th, he published an essay arguing that the entire tech industry must work together to "slow the pace" of AI development.

That's the CEO of the company whose product was just used to hack a rival AI company, publicly calling for a slowdown, one week before his product was used to hack a rival AI company. The timing is not great, Dario.

To be fair, Anthropic did not conduct the hack, and Claude being capable enough to assist security researchers is not inherently a knock on Anthropic. But the episode does illustrate the exact problem Amodei keeps describing: these tools are powerful, they're out in the world, and the guardrails have not kept pace with the capabilities.

OpenAI Took It Seriously. The Industry Probably Won't.

OpenAI's response here was actually reasonable. They paid the bounty promptly, patched the vulnerability fast, and issued a statement thanking the researchers. That's how responsible disclosure is supposed to work, and they did it.

The bigger issue is systemic, not specific to this incident. Hacktron AI said they worked with both OpenAI and Discourse to coordinate the patch and appreciated the "fast resolution." Great. One hole plugged. How many are left? Neither Anthropic nor OpenAI responded to CBS News' requests for comment on the broader implications.

Bug bounties and fast patches are reactive. The industry builds, deploys, monetizes, and then figures out the security later, if someone finds it and reports it honestly. Hacktron AI reported it honestly. The next group might not.

The Dingo Take

You are supposed to believe that the AI industry is moving fast because it has to, because if the Americans don't build it first the Chinese will, because the benefits outweigh the risks, because the smartest people in the room have it under control. And then one week after the CEO of a leading AI company publishes an essay about slowing down, his company's chatbot gets used to rummage through a competitor's source code repositories in 72 hours flat.

This is the actual state of play. The tools are real, the capabilities are significant, the security infrastructure is visibly lagging, and the people who built these systems are, by their own public admission, worried about what they've built. Amodei isn't a crank shouting from the outside. He runs the company. When the person who made the thing tells you the thing is dangerous, that's probably worth more than a shrug and a product update.

The $6,500 bounty OpenAI paid out is a genuinely funny number in context. The company is valued at roughly $300 billion. They paid less than a used Honda Civic to find out their internal systems could be breached by a competitor's chatbot over a long weekend. Sleep well.

Sources