Tech Brew Ride Home - OpenAI Got Hacked By... AI
Episode Date: September 18, 2026Security researchers used Claude to hack into OpenAI's private code repository through a bug bounty program, OpenAI launched Astra for Law for select firms, Anthropic redesigned Claude projects to run... parallel agent threads, and opened a Bay Area biology lab. Security researchers in an OpenAI bug bounty program hacked OpenAI, accessing its "monorepo" on GitHub, using a cybersecurity version of Opus 4.8 and Opus 5 (The Wall Street Journal) OpenAI launches Astra for Law, combining GPT-6 Astra with a legal search index and instructions for legal analysis and writing, initially for select law firms (OpenAI) SiliconANGLE reports Astra for Law passed 54% of legal-research benchmark questions versus 38.7% for base GPT-6 Astra, launches with 26 partner-built plugins connecting Relativity, Clio, and iManage, and brings ChatGPT for Word to general availability (SiliconANGLE) Anthropic redesigns Claude projects, letting users describe work in one conversation and have Claude manage it across parallel threads, starting in Claude Code (Anthropic) The Verge reports each project thread runs as its own Claude Code cloud session on a separate repo branch, with a coordinator resolving overlapping work as merge conflicts, and beta access starting today for select Claude Pro and Max subscribers (The Verge) Anthropic Life Sciences Head Eric Kauderer-Abrams says the AI company set up a Bay Area wet lab for physical biology work, as it pushes into AI disease research (Reuters) Longreads Theoretical computer scientist Scott Aaronson says he's heard rumors that AI labs are sitting on major unpublished math solutions, and describes a mathematics community consumed by anxious conversation about the "AI tsunami" after the hostile response to a recent Navier-Stokes proof (Shtetl-Optimized) The FT reports the AI boom is fueling a resurgence in VC bets on "moonshot" sectors like nuclear fusion and brain-computer interfaces, as Dealroom data shows non-AI deep-tech funding has topped $150B since the start of 2024 (Financial Times) Subscribe to the ad-free feed.
Transcript
Discussion (0)
Welcome to the Tech Brew Ride Home for Friday, September 18th, 2026. I'm Brian McCullough today. Security researchers used Claude to hack into OpenAI's private code repository through a bug-bounding program. OpenAI launched Astra for law for select firms, anthropic redesigned Claude projects to run parallel agent threads and open a Bay Area Biology Lab. Here's what you miss today in the world of tech.
Every day shareholders meet to discuss important matters about the companies you invest in. Now you can.
can make your voice heard too. Vanguard investor choice makes it easy to set your proxy voting preference
for your eligible Vanguard index funds, whether you hold a Vanguard fund directly or through another
brokerage firm. All it takes is a few clicks to select your proxy voting preference and be heard
on important shareholder topics like executive pay and director elections. Visit vanguard.com
slash investor choice to learn more. It's your shares. It's your voice. It's easy. Vanguard investors own
shares of our index funds and those funds own shares of the companies they invest in,
Vanguard Marketing Corporation distributor.
Well, maybe OpenAI is freaking out about how far AI has advanced because they
themselves have been hacked by AI, quoting the journal.
Two weeks after a swarm of AI agents broke out of containment at OpenAI to hack the company
hugging face, the chat GPT maker learned about another AI powered intrusion, and this time
it was the target.
independent security researchers had used Anthropics Clod software to gain access to an OpenAI employee's
chat GPT account, giving them a way to read and suggest changes to the company's private cash of software.
The team who participated in an OpenAI bug hunting program that offers a safe harbor for researchers
to attempt to break into a corporate system quickly reported their findings to the company.
The team to which OpenAI paid a $6,500 bounty disclosed their work for the first time,
the Wall Street Journal. At a time when the U.S. is engaged in a race with China for AI supremacy,
the researchers that hacked open AI said the attack suggests that advanced cyber-savvy teams
backed by nation-states have a very real chance of getting a peek at the country's AI secrets.
I don't think we are as strong as Chinese threat actors, said Mohan Pat Hapati, chief technology
officer with Haktron AI, the security firm that did the research. We're just three guys
with Claudex subscriptions. OpenAI said the hackers had uncovered a pair of issues, one in a third-party
service called Discourse that hosts OpenAI's Community Discussion Forum, and a second with the AI
company itself. Both of these are now resolved, Open AI said. We thank the researchers for contacting us
and sharing their findings. We narrowed the permissions on community sign-in tokens and revoked
affected tokens and sessions, the company said. An anthropic spokesman declined to comment.
Cyber researchers regularly participate in bug bounty programs, which stress test major companies' digital infrastructure.
The hack of OpenAI began on July 23rd when Hactron's researchers found a bug in the way that the Community Discussion Forum discourse processed certain image files.
The researchers had access to a special version of Claude Opus 4.8 made available to qualified cybersecurity practitioners,
and they asked it to write code that would exploit this bug in a cyber attack.
At first, it didn't work.
That evening, however, Anthropic released Opus 5, and by the next day, Claude had found a way to exploit the bug.
The attack code it produced allowed the researchers to gain access to a discourse server hosting OpenAI's discussion forums,
where they were able to access users' authentication tokens, the unique digital strings of letters and numbers that allow people to gain access to online services.
To their surprise, these tokens were valid on chat sheet, BT, and some of them belonged to OpenAI employees.
The tokens could also be used to access OpenAI's GitHub service, a software repository because they didn't want to access sensitive data.
The researchers can't say for certain what the OpenAI source code system was used for, but they said it was named Mono repo.
Mono repo, according to people familiar with OpenAI's architecture, is a large software repository of OpenAI's algorithmic secrets.
It is the software equivalent of the company's secret sauce, which makes its models faster and more efficient, but it isn't thought to contain the model weights, which are the equivalent of OPECALS, which are the equivalent of OECRICS, which makes its models faster and more efficient, but it isn't thought to contain the model weights, which are the equivalent of
Open AIs crown jewels, the people said.
These are trillions of numbers at the core of the large language models that help them
understand which pieces of information to amplify and which to ignore.
Using chat cheap E.T as their interface, the researchers could read files in mono repo.
The researchers said they stopped their hack once they realized that they could access sensitive
data, but not before they made what's known as a pool request.
They instructed the chatbot to send a pool request or suggested change to a documentation
file in the repository. The team suggested an update that would have changed the documentation
file to include the words HECTron AI team, POC, and a link to their X accounts. It was their proof
that they had gained access to Open AI's secrets, they said. The suggested change wasn't
accepted, the researchers said, Open AI said its review of GitHub found limited reads of private
repository metadata and code changes. Discourse said it fixed the security issue on July 25th the same
day it was notified. The hack demonstrates the complexity of defending corporate secrets in the age of
AI hacking, said Joshua Sacks, the chief technology officer with the AI security company Abundant Security,
who reviewed Hactron AI's report on the incident. The world's software is rife with security
bugs. The reason we haven't discovered them all is because until last year there were only a few
thousand people who were expert at finding those bugs, he said. Now AI agents are making that
capability available to people who are less skilled, sex, said.
end quote.
OpenAI has launched Astra for Law, combining GPD6 Astra with a legal search index and instructions
for legal analysis and writing initially just for select law firms, quoting Silicon
angle.
Astra for Law is not a new model.
The company has wrapped GPT6 Astra in a legal search index and a set of instructions for
legal analysis, then offered the result to law firms and the software company.
that sell to them. The index reaches U.S. case law, statutes, regulations, court rules, and
administrative decisions across more than 230 million URLs with sources added daily. The nonprofit-free
law project's court listener database supplies the case law. The benchmark opening I chose
rewards finding the right authority and the right passage inside it. Astra for Law passed
the overall correctness check on 54% of 200 questions drawn from the
the private validation set of Val's AI legal research bench. GPT6 Astra with web search alone managed
38.7% on the same questions with both systems run at their highest reasoning effort.
On case law questions, it found 24% more reference cases. On a separate audited set, it retrieved
up to 54% more of the target passages from correct opinions. Initial access is limited.
Selected firms reach it through a trusted access program in Chad GPT and Codex, where it
shows up in the model picker as GPT6 Astral Law. An application programming interface version,
GPD6 Astral Law is due later with no date on pricing attached. Legal AI companies,
Harvey Technologies, and Ligora AB are named as API customers for it. For eligible firms,
the offering carries zero data retention on the API and chat GPT enterprise usage is excluded
from human review by default. Latham and Watkins is working with OpenAI on governance design
for information permissions, ethical walls, and client instructions.
26 partner-built plugins launched alongside the model,
connecting ChatGPT to tools such as Relativity, Clio, I Manage, and Deep Judge,
while Thompson Reuters is bringing high-Q matter context into ChatGPT
and previewing a connector for its co-council legal product.
An additional nine plugins came from lawyers and legal engineers outside the vendor set,
carrying 47 Custom Skills.
ChatGPT for Word reached general availability,
ability the same day. Joel Ron, chief technology officer at Thompson Reuters, said the link between
chat GPT and legal tools is only part of what firms need. As AI becomes more open and interoperable,
the value is not in the connectivity alone, he said. Legal professionals need more than access to
information. They need trusted, intelligence, relevant enterprise, and matter context, purpose-built
legal capabilities, and the governance required for high-stakes work. Open AI engineers embedded at
individual firms have also been building firm-specific tools on ChatchipT Enterprise.
Sullivan and Cromwell has an agreement analyzer that pulls its negotiating playbooks and
selected precedents into the review of a new deal and turns what it finds into
proposed red lines. At Ropes and Gray, the work went into deal diligence. Coolie's tool
go public handles initial public offering preparation, drafting the filings included.
John Svah, a Sullivan and Cromwell partner who's
saw early build said the model showed impressive research, depth, and sensitivity to authority.
OpenAI described the launch as the start of a long-term investment into law.
GPD6 Astra itself started rolling out two weeks ago on September 3rd, end quote.
Fall is almost here, which means less time in the sun and way more time in your car.
Whether you're headed to a big meeting, picking up the kids from school, or starting your cross-country road trip,
You'll want to stay connected on your drive.
With AT&T connected car, your eligible vehicle can become a Wi-Fi hotspot
so you and your passengers can happily stream, browse, and even email from the road.
Got a gamer in the backseat, help keep them connected and in the game with AT&T connected car.
Being on the road more doesn't mean you have to put your whole life on pause,
stay connected no matter where you're going.
See if your car is eligible at ATT.com slash tech brew.
That's ATT.com slash tec brew.
That's ATT.com slash tec.
TechBrew requires eligible vehicles, service and coverage not available everywhere.
Restrictions apply.
AI can clone your voice, forge your signature, and even create fake documents that look real
enough to convince an expert.
It's called title fraud, and it's how criminals are stealing from homeowners.
Here's how it works.
Your property records are public by law, which makes it easy for scammers to get your
records, use AI to forge a transfer document, and make themselves the new legal owner of
your property.
Protect your property with home title lock. They monitor your property titles 24-7 and alert you of any changes. If you're a victim of fraud, they'll spend up to $1 million to restore it.
Get a free title history report, plus a 14-day free trial at hometidallock.com slash TBRH. That's home-titlelock.com slash TBRH.
Anthropica has redesigned Claude Projects, letting users describe work in one conversation and have Claude Managing.
it across parallel threads starting in Claude Code, quoting the verge.
The revamped projects feature in Claude Code allows users to run multiple agents under the
same roof with a shared memory, goals, and library of files and artifacts.
Similar to Grokbot and other tools that manage groups of AI agents, each project has
threads running different tasks in parallel with a coordinator directing everything.
Under the hood, each thread is a Claude Code cloud session working on its own branch and copy
of the repo, the coordinator keeps work organized, but if any threads work on the same code,
the overlap is resolved as a merge conflict, just like any other PR. Each thread can further
split its delegated work into pieces using subagents, loops, and workflows when needed,
so large assignments finish faster. Users can interact with each thread individually,
or monitor and update things through the main project chat. At launch, threads run in the cloud,
but Anthropics says support for local tools and code is coming very soon.
The updated projects feature is available in beta starting today for select Claude Pro and
Max subscribers with access expanding to all Pro Max team and enterprise users later, as well as
co-work and regular Claude Chats, end quote.
Anthropic life sciences head Eric Cowderer Adams says the AI company has set up a Bay Area
Wet Lab for physical biology work as it pushes into AI disease research.
Quoting Reuters, the move represents a small step,
toward Anthropics' enormous ambition to tackle diseases that it thinks the pharmaceutical industry
is neglecting, and to do so before staff and the public lose faith that AI justifies,
erasing jobs, and possibly human life, one of the people said. The success of any drug program
it runs is not certain. Most drugs fail to pass trials for clinical safety and efficacy.
For Anthropic CEO Dario Amo Dai, the effort is personal. A disease killed his father only a few
years before a cure came about, he said in a recent essay, Caldera Abrams echoed the sentiment.
The mission of the company is to develop powerful AI in such a way that it benefits the world,
Caldera Adams said. By far, we see the biggest opportunity for that in the life sciences,
and that is motivating everything that we're doing. Like other biotech companies, Anthropic
is embracing physical automation, said the two people who spoke on condition of anonymity.
The startup wants to push how its clawed AI can direct robotic units to carry a
out science experiments with limited human intervention, one of the people said. Still, Anthropic
believes that human oversight and involvement are essential for safety, its spokesperson said. We're in
the very early innings of using AI to automate the execution of lab work, said Calderer Adams,
an area that has the potential to bring about meaningful acceleration in so many different processes.
Anthropics staked out its intention to start running drug programs at a San Francisco event in June.
On stage there, Caldera Adams said Anthropic would do pre-clinical work in areas that
that traditional companies did not find attractive financially.
The company also launched software called Claude Science,
and it earlier added Novartis CEO Vass Narahasemann to its board
and bought the startup coefficient bio for about $400 million in stock,
according to media reports.
Anthropic confirmed the acquisition,
which will help it build tools for drug development,
but it had no comment on the deal price.
Now, Anthropic is bulking up its in-house lab efforts for speed,
and for firsthand experience in biology, though it outsources work when efficient,
Kaudera Adams told Reuters.
There are some things that we can do much faster in our own hands, he said, with the goal
to operate at the largest possible scale.
His view is that AI could fast-track development for conditions previously thought to be undruggable
too difficult to treat.
The technology could speed discovery, for instance, of bi-specific and tri-specific antibodies,
complex molecules that can be directed at multiple points on a targeted protein or cell,
or hit multiple targets. The precise diseases Anthropic is addressing and its progress remain unclear.
Once a molecule is identified, it can take years to bring a drug to market as it is tested in human
trials, a challenge that Anthropic has not yet taken on. Isomorphic Labs, the drug discovery arm
of rival Alphabet, has worked for years to get to the clinic and earlier delayed that goal to the end
of 2026. In its efforts at Lab and other industry automation, Anthropic launched the Model Hardware
Standard in August, which helps AI operate equipment.
a release out of academia called PILAB robot, unrelated to Anthropic, earlier addressed related, though different automation needs, end quote.
Time for the weekend Long Reads suggestions.
A theoretical computer scientist named Scott Aronson says he has heard rumors that AI labs are sitting on major solutions to math problems after a hostile response to that whole Navier-Stokes proof.
quote, let me try to convey the mood in the mathematical community right now, at least as far as
my experience reaches. Nearly every conversation is about the AI tsunami or eventually circles
around to the tsunami, even if it's originally about something else. Often though, the focus
is less on the unknowable future for how much longer will mathematical research as a human
enterprise even exist, then on the immediate questions of how to respond, end quote. And from the
Financial Times, a look at how the AI boom is fueling a resurgence in VC bets on so-called moonshot
sectors. Deal Room says non-AI deep tech funding has topped $150 billion since the start of
2024. Quote, the AI boom is fueling a resurgence in ambitious, so-called moonshot bets,
as early SpaceX backers huge returns and falling valuations for traditional software companies
forced tech investors to embrace riskier and more capital-intensive deal-making.
Ideas once considered outlandish from nuclear fusion to melding humans with machines
are gaining attention from venture capital firms that even a few years ago would never
have touched startups in such sectors. The world definitely has changed, said Matt Robinson,
partner at VC firm, Acell. Look inside any VC's office and the kind of companies they are
discussing over the last couple of years has transformed. Excluding the giant sums
plowed into AI startups, global investment in deep tech, companies whose products are rooted in
big scientific or engineering advances, has exceeded $150 billion since the start of 20204, more than the
$133 billion in the entire decade to the end of 2019, according to Deal Room. Ambitious founders in Silicon
Valley are cheering a return to greater risk-taking from investors after an extended stretch following
the dot-com bust in which VCs became preoccupied with backing predictable enterprise software companies,
The most profitable startups to invest in were all software businesses on the internet for a period of time when the internet was new and growing, said Max Hodak, co-founder of science, a brain computer interface startup that sucked a lot of oxygen out of physical hardware because it's harder. Was that totally healthy? Probably not, but we're back. Hodak, who also co-founded Neurrelink alongside Elon Musk, argues that VC's interest in software itself was a detour from the hardware ventures that helped
Silicon Valley emerged decades ago. The original OG venture capital built the railroads. This is really
the magic of capitalism, he said, end quote. No weekend bonus episodes for you this weekend. Talk to you on
Monday.
