Claude Code, Copilot and Codex all got cracked. Every attacker went for the credential, not the model.

Claude Code, Copilot and Codex all got cracked. Every attacker went for the credential, not the model.
Published in : 30 Apr 2026

Claude Code, Copilot and Codex all got cracked. Every attacker went for the credential, not the model.

On March 30, BeyondTrust proved that a crafted GitHub branch name could steal Codex’s OAuth token in cleartext. OpenAI classified it Critical P1. Two days later, Anthropic’s Claude Code source code spilled onto the publi...

Read full article from source