The immediate backdrop is the wider US–Israel campaign against Iran that began with coordinated strikes in March 2026, which Washington and Jerusalem said they carried out after citing intelligence of imminent threats and a pattern of attacks by Iran-linked forces against regional infrastructure and allied assets.
Structurally, that campaign sits atop decades of sanctions and diplomatic ruptures that have shaped technology and national-security policy: the US withdrawal from the Iran nuclear deal (JCPOA) on May 8, 2018, the consequent reimposition of broad sanctions, and successive US executive actions tightening export controls and cyber authorities.
Three independent security researchers at Hacktron used Anthropic’s Claude Opus 4.8 and 5 to compromise OpenAI employee accounts and gain access to OpenAI’s internal GitHub repository, called “Monorepo,” in under 72 hours, The Verge reports.
According to The Verge’s account of reporting by The Wall Street Journal, the researchers stopped short of browsing or exfiltrating internal source code; instead they submitted a pull request and disclosed the vulnerability they discovered.
The account names Anthropic’s Claude models as the automation the researchers relied on to compromise accounts and escalate access, and it describes the team as independent operators affiliated with Hacktron, a detail repeated in the coverage (per The Verge).
OpenAI’s Monorepo houses centralized code and tools for the company’s projects; The Verge notes the researchers gained access to that repository rather than to isolated external assets (per The Verge).
The disclosure route the researchers took—sending a pull request rather than downloading code—frames the incident as a security proof-of-concept and responsible disclosure rather than an exploit for public exposure, according to the reporting (per The Verge).
This episode raises immediate questions about how generative AI assistants can be weaponized in account-takeover workflows and whether internal defenses and employee account protections at major AI firms are keeping pace with attacker tooling, a concern underscored by the quick timeline from initial access to repository entry (per The Verge).