What jumped out at me wasn’t “Claude hacked OpenAI.” It was how hard the headline is trying to turn a narrow security exercise into a morality play about model rivalry. The interesting part, at least to me, is much less cinematic: a pair of vulnerabilities got chained together, and an LLM helped do the chaining faster than a human team probably would have done alone. That’s useful. It’s also not the same thing as an AI spontaneously becoming a super-hacker.
I’m a little skeptical of the theatrical read here because the source description already does a lot of work. “Under 72 hours” sounds impressive until you ask what that includes, what the researchers already knew, and how much of the path was just disciplined exploitation of a pretty ordinary attack surface: an image upload on a forum, then a route into an internal GitHub repo. That’s not nothing. But it’s also not proof that model intelligence, by itself, has crossed some clean threshold. It may simply show that agents are getting better at tedious exploitation workflows. That’s still bad news for defenders, just a more specific kind.
The part I’d actually care about is the operational implication. If Claude Opus 5 can be used to stitch together a vulnerability chain quickly, then the cost of turning “maybe exploitable” into “definitely weaponized” drops. That matters more than the brand-name drama. Security teams already know that single bugs are bad; chained bugs are where things get ugly. If the model helps compress that work from days into hours, then the pressure shifts toward faster patching, tighter upload handling, and much more boring but important internal segmentation.
I also think the headline is doing Anthropic a favor it probably doesn’t deserve. If the point is that Opus 5 was good enough to assist a real exploit chain, fine. If the point is “Claude couldn’t hack OpenAI until Anthropic shipped a better Claude,” that feels more like marketing copy than analysis. Maybe that was the point of the piece, but I don’t buy the implicit leap from one demo to some grand statement about model capability.
What I’d want to see next is not another dramatic headline, but the boring details: which vulnerability classes were involved, what the researchers prompted the model to do, where it failed, and how much human steering was still required. That’s the difference between a useful signal and a PR-grade anecdote.
Reference: Claude couldn't hack OpenAI. Then Anthropic shipped Opus 5.