3 Indian-origin researchers used Claude to breach OpenAI systems in 72 hours

Three Indian-origin cybersecurity researchers at Hacktron AI used Anthropic’s Claude models while investigating vulnerabilities that ultimately gave them access to OpenAI employee accounts and a private GitHub environment, according to reports. Ha...

  AI generated image used for representation.

Three Indian-origin cybersecurity researchers demonstrated how Anthropic’s Claude AI could be used to chain security vulnerabilities and gain access to OpenAI employee accounts and an internal software repository, according to a report by The Wall Street Journal.

Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, who work at cybersecurity startup Hacktron AI, conducted the research in July 2026 while examining security weaknesses at major artificial intelligence companies. The researchers said they moved from OpenAI’s public community forum to employee ChatGPT and Codex accounts before reaching the company’s private GitHub environment.

The researchers said the entire process, from identifying the initial weakness to demonstrating access to OpenAI’s internal repository, took less than 72 hours. They spent less than $3,000 on AI model tokens during the work and received a $6,500 bug bounty from OpenAI after reporting the vulnerabilities.


Also Read: Fired employee claims company paid $15,000 to walk away, then asks about missing $380,000, stuns HR

How the researchers reached OpenAI’s internal systems

The investigation began with community.openai.com, OpenAI’s community and help forum, which runs on the third-party Discourse platform.

Hacktron’s researchers found that specially crafted HEIC and HEIF image files could be used to exploit a vulnerability in image-processing software used by Discourse. The flaw was associated with the libheif image-decoding library and could enable remote code execution, allowing an attacker to execute commands on the affected server.
ADVERTISEMENT

However, taking control of the forum server did not by itself provide access to OpenAI’s internal code. The researchers subsequently chained the vulnerability with a separate identity-related weakness that allowed them to move into OpenAI employee accounts.

They said they eventually gained access to ChatGPT and Codex accounts belonging to OpenAI employees. One of those Codex accounts was connected to OpenAI’s internal GitHub environment.

Rather than examining sensitive source code, the researchers said they used the compromised Codex account to create a harmless pull request in OpenAI’s private repository as proof that the access was genuine.

Claude helped accelerate the research

Anthropic’s Claude models played a central role in the researchers’ work. The team said it used Claude to help write, debug and adapt binary exploits during the investigation, spending less than $3,000 on API tokens.
ADVERTISEMENT

The research demonstrated how AI-assisted tools can reduce the time required to develop and troubleshoot complex exploits. TechCrunch reported that the researchers initially struggled to produce a working exploit with an earlier Claude model, but succeeded after Anthropic released Opus 5.

The researchers were operating under OpenAI’s bug-bounty programme and reported the vulnerabilities to the companies involved. OpenAI subsequently addressed the identity-related issue and awarded the team a $6,500 bounty. Reporting on the incident said OpenAI also revoked affected authentication tokens and sessions.
ADVERTISEMENT

In a statement to Forbes, OpenAI spokesperson Drew Pusateri thanked the researchers for reporting the findings and said the company had resolved the vulnerability.

Also Read: 9 PSU banks including Canara Bank, Indian Bank to merge with SBI, PNB, Bank of Baroda? PIB responds

‘No brand name, colleges or companies’

The incident also drew attention to the professional backgrounds of the three researchers.

Tech commentator Deedy Das highlighted that the researchers’ LinkedIn profiles did not feature prominent college names or major technology companies. In a post discussing the incident, Das wrote: “Here are the LinkedIns of the 3 Indian guys who hacked OpenAI with Opus 5 in 2 days for <$3000.”

The episode has since prompted discussion around how AI-assisted cybersecurity is changing the skills and resources needed to investigate sophisticated vulnerabilities. The researchers’ work showed that a small team could use commercially available AI tools to accelerate a complex vulnerability chain, while operating within a bug-bounty framework and reporting the findings to OpenAI.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › Trending › 3 Indian-origin researchers used Claude to breach OpenAI systems in 72 hours
Text Size:AAA
Success
This article has been saved

*

+