News

How 3 Indian-origin researchers used Claude to breach OpenAI systems

Researchers from cybersecurity startup Hacktron AI used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems during an authorised security test, gaining access to employee accounts and demonstrating a route into a private code repository.

Written by : TNM Staff

Three Indian-origin cybersecurity researchers, including one from Andhra Pradesh, used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems and gain access to employee accounts and a private GitHub repository as part of an authorised security test, according to media reports.

The researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — are associated with cybersecurity startup Hacktron AI. According to Hacktron AI, Jaiswal led the research, with Pedhapati and Maini working with him.

The team was testing OpenAI’s systems under its bug-bounty programme, which rewards researchers for finding and responsibly reporting security vulnerabilities. The researchers spent about three months on the broader research before identifying a critical vulnerability in July, according to The Times of India.

The research began with OpenAI’s public community forum, which runs on third-party software called Discourse. The researchers found a vulnerability in the way the forum processed certain image files.

A specially crafted image could be used to gain control of the forum’s server. The team then used Claude to help investigate the vulnerability and develop an exploit.

The researchers began the work on July 23. Their initial attempts to exploit the vulnerability did not work, but they subsequently found a way to exploit it after Anthropic released its Opus 5 model.

The researchers then identified a separate weakness involving OpenAI’s single sign-on system. This allowed them to obtain authentication information linked to ChatGPT and Codex accounts belonging to OpenAI employees.

This provided a route into OpenAI’s private GitHub environment through an employee account. According to reports, the researchers demonstrated that they could access the company's internal code repository but did not download or examine its source code.

Instead, they used an employee’s Codex account to submit a pull request to the private repository, demonstrating that the access was possible.

The entire operation took less than 72 hours from the discovery of the vulnerability to reaching the private repository. The researchers spent less than $3,000 on AI tokens during the test.

OpenAI subsequently fixed the vulnerabilities, revoked the affected access and paid Hacktron AI a $6,500 bug bounty for the findings.

The researchers stressed that Claude did not independently hack OpenAI. Human researchers found the vulnerabilities, connected them and decided how to use the access they obtained. Claude was used to assist with tasks including investigating the vulnerability, writing, debugging and adapting exploit code.

Hacktron also used other AI models during the research. The incident therefore involved human researchers using multiple AI tools rather than an autonomous AI system independently attacking OpenAI.

Who are the three researchers?

Harsh Jaiswal is a co-founder of Hacktron AI and a vulnerability researcher with more than 10 years of experience in finding security flaws. He has previously worked as a security engineer and researcher at Project Discovery, Zomato and Cure53, and has participated in bug-bounty programmes through HackerOne.

His work has included identifying vulnerabilities in products and platforms from companies including Apple, PayPal and GitHub. Jaiswal and Maini had also previously worked together on security research.

Mohan Pedhapati (26) is the co-founder and chief technology officer of Hacktron AI. He is from Rajamahendravaram in Andhra Pradesh and completed his schooling at Zilla Parishad High School in Sampathnagaram before studying computer science at Rajiv Gandhi University of Knowledge Technologies (RGUKT), Nuzvid.

Pedhapati began participating in Capture the Flag competitions while at RGUKT and later captained the university's team, Invaders. He subsequently joined a Japanese competitive hacking team and qualified for the finals of a Google hacking contest.

His cybersecurity research includes work on a software vulnerability known as prototype pollution, which was ranked fourth in PortSwigger's 2021 list of popular web-hacking techniques.

Pedhapati later founded Electrovolt Infosec, a cybersecurity research team, before working as a security consultant at German security firm Cure53.

In August 2025, Pedhapati co-founded Hacktron AI with Jaiswal and Zayne Zhang. The startup focuses on using artificial intelligence to automate vulnerability hunting and continuously test software as it changes.

Hacktron was among the first six startups selected for Project Europe, an accelerator that invested 200,000 euros in the company. In May, the startup raised $2.9 million and reported about $240,000 in revenue during its first nine months.

Pedhapati is now based in Hyderabad and has secured an O-1 visa to move to the US next year.

Speaking to The Times of India about the OpenAI research, Pedhapati said the vulnerability highlighted the importance of ethical security research as AI systems become increasingly important to critical technologies. “Vulnerabilities of this kind, if discovered and exploited by malicious actors or hostile states, could have serious consequences for national security,” he said.

He also said the research showed how AI was changing cybersecurity. “The process also illustrates a larger shift in cybersecurity. AI is making sophisticated hacking capabilities increasingly accessible to small teams, potentially compressing work that once required months and much larger groups of researchers,” Pedhapati said.

Rahul Maini is a vulnerability researcher at Hacktron AI and has worked in the bug-bounty and penetration-testing community. His previous experience includes Cobalt, Synack Red Team, HackerOne and Bugcrowd.

Maini has received recognition including an AT&T Hall of Fame mention and a Bugcrowd community award. He was also the first runner-up at TCS HackQuest 3.0. He studied computer science at Bharati Vidyapeeth in Delhi.

Jaiswal, Maini and Pedhapati have collectively worked on vulnerabilities affecting widely used technology platforms. The Hacktron researchers have also reported vulnerabilities in software used by companies including Perplexity AI and Supabase.