Let's talk: editor@tmv.in
3 Indians Used Claude To Hack OpenAI In Just 3 Days

3 Indians Used Claude To Hack OpenAI In Just 3 Days

Yekkirala Akshitha
September 22, 2026

Three Indian-origin cybersecurity researchers used Anthropic’s Claude to uncover vulnerabilities in OpenAI’s systems, gaining access to employee accounts and the company’s private GitHub environment. Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, from cybersecurity startup Hacktron AI, were conducting an authorised bug-bounty security test. OpenAI later paid the team a $6,500 (around Rs 6.2 lakh) bounty.

The entire exercise took less than 72 hours. The researchers reportedly spent under $3,000 on AI tokens while testing the vulnerabilities. They began by examining OpenAI’s public community forum, which runs on Discourse, and found a flaw involving the processing of certain image files. The vulnerability could allow code execution on the forum’s server.

The team used Claude to investigate the flaw and help write, debug and adapt an exploit. Their initial attempts did not work, but after Anthropic released Opus 5, they were able to develop a working exploit. The researchers then discovered a separate weakness involving OpenAI’s single sign-on system, allowing them to obtain login tokens linked to employee ChatGPT and Codex accounts. This provided a path into OpenAI’s private GitHub environment.

Harsh Jaiswal, a Hacktron co-founder, has more than 10 years of experience in vulnerability research. He has worked with Project Discovery, Zomato and Cure53 and participated in HackerOne bug-bounty programmes. His research has included vulnerabilities affecting Apple, PayPal and GitHub.

Mohan Pedhapati, Hacktron’s co-founder and CTO, specialises in web exploitation, source-code review and mobile security. He previously founded Electrovolt Infosec and worked as a security consultant at Cure53. He studied computer science at RGUKT Nuzvid.

Rahul Maini is a vulnerability researcher with experience at Cobalt, Synack Red Team, HackerOne and Bugcrowd. He has received an AT&T Hall of Fame mention and a Bugcrowd community award and was first runner-up at TCS HackQuest 3.0. He studied computer science at Bharati Vidyapeeth in Delhi.

The researchers said Claude assisted with the technical work, but they themselves connected the vulnerabilities and decided how to use the access. OpenAI subsequently fixed the flaws, which included a vulnerability in its community forum’s image-processing system that enabled code execution and a weakness in its single sign-on system that exposed authentication information linked to employee ChatGPT and Codex accounts.

3 Indians Used Claude To Hack OpenAI In Just 3 Days - The Morning Voice