A bold cybersecurity operation recently highlighted the growing capacity of artificial intelligence to serve as a sophisticated attack vector. The startup Hacktron AI, commissioned for an authorized penetration test, successfully compromised several employee accounts at OpenAI. Within just 72 hours, the researchers managed to infiltrate the company's internal systems, chaining two distinct vulnerabilities to access critical tools like ChatGPT and Codex. This show of force allowed the experts to inject a harmless code modification into the company's central repository, proving the viability of their attack vector.

The most striking aspect of this intrusion lies in the intensive use of AI to automate the hacking process. To breach OpenAI's defenses, the researchers first leveraged Claude, the model developed by Anthropic, to generate the code necessary to exploit the flaws. In a technological twist of irony, they then used GPT-5.6 Sol, the target's own flagship model, to steer the subsequent stages of their progress within the infrastructure. This reliance on generative AI illustrates a new reality: the drastic reduction in the time and human resources required to conduct high-level cyberattacks.

Although this operation was part of a bug bounty program aimed at strengthening security, the stakes go far beyond the $6,500 reward paid to Hacktron AI. OpenAI confirmed that it had patched the identified gaps, noting that no sensitive data had been extracted. However, this vulnerability highlights a systemic risk: the offensive potential of language models, which are now capable of accelerating complex operations that previously required months of preparation by specialized teams.

This case adds to a series of recent incidents, such as the test hack of Hugging Face or the discovery of cryptographic flaws via Anthropic's Mythos model. For experts, the conclusion is clear: AI is a total game-changer for cybersecurity. While these technologies offer unprecedented defensive tools, they also provide attackers with ten-fold reconnaissance and execution capabilities. These developments require companies in the tech and blockchain sectors to be increasingly vigilant against threats now capable of learning and adapting in real time.