San Francisco, USA – September 20, 2026 – In a significant demonstration of the evolving landscape of cybersecurity and the dual-use potential of artificial intelligence, a team of three Indian-origin cybersecurity researchers from the startup Hacktron AI successfully breached OpenAI’s systems. Utilising Anthropic’s advanced AI chatbot, Claude, the ethical hackers uncovered critical vulnerabilities within OpenAI’s infrastructure, gaining unauthorised access to employee accounts and private GitHub repositories in an impressive display of speed and skill. This authorised penetration test, conducted as part of OpenAI’s bug bounty program, took less than 72 hours, costing the researchers a mere fraction of the eventual bounty they received.

The incident underscores the paramount importance of proactive security measures, even for leading technology companies at the forefront of AI development. It also highlights the growing role of AI tools in accelerating and refining the process of vulnerability discovery and exploitation for both defensive and offensive cybersecurity operations.

The Breach Unveiled: Main Facts

The core of the story revolves around the swift and successful security assessment carried out by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, all affiliated with the cybersecurity firm Hacktron AI. Their mission, sanctioned by OpenAI, was to identify and report security flaws within the company’s vast digital ecosystem. What they achieved, however, was a penetration far deeper than many might have anticipated, especially given the limited timeframe and resources expended.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

Within just three days, the trio identified a critical flaw in OpenAI’s public community forum. This initial vulnerability, related to the handling of specific image files, provided an entry point. Crucially, instead of relying solely on traditional manual methods, the researchers ingeniously integrated Anthropic’s Claude into their toolkit. Claude proved instrumental in dissecting the vulnerability, generating, debugging, and adapting exploit code. This AI-assisted approach allowed them to quickly develop a working exploit.

Further probing led them to uncover a secondary weakness: the ability to leverage login tokens to gain access to OpenAI employee accounts. This second layer of access proved to be the gateway to the company’s private GitHub environment, facilitated through an employee’s Codex account. The entire operation, from initial discovery to deep access, was completed with remarkable efficiency, demonstrating the potent combination of human ingenuity and advanced AI assistance.

OpenAI, in line with its commitment to security and its bug bounty program, swiftly addressed the identified vulnerabilities upon receiving the detailed report from Hacktron AI. The company subsequently awarded the team a bounty of $6,500, acknowledging the invaluable contribution to enhancing their security posture. The researchers’ expenditure on AI tokens during the test was reported to be less than $3,000, illustrating a significant return on investment for their expertise and innovative methodology.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

The Unfolding Narrative: A Chronology of the Breach

The successful penetration of OpenAI’s systems by Hacktron AI’s team was a meticulously executed sequence of steps, highlighting their systematic approach and the decisive role played by AI.

July – Initial Reconnaissance and Vulnerability Discovery: The journey began in July when the Hacktron AI team, comprising Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini, initiated their authorised security assessment of OpenAI’s systems. Their focus was broad, aiming to identify any potential weaknesses that could be exploited. Early in their reconnaissance, they zeroed in on a specific vulnerability within OpenAI’s public community forum. This flaw was critically linked to how the forum processed and handled certain image files uploaded by users. Such vulnerabilities often arise from improper validation of file types, sizes, or embedded metadata, potentially leading to remote code execution (RCE) or other severe security compromises. The team’s keen eye for detail allowed them to pinpoint this subtle yet significant entry point.

Leveraging Claude: AI-Assisted Exploit Development: Having identified the initial vulnerability, the researchers faced the challenge of developing a robust and reliable exploit. This is where Anthropic’s Claude entered the scene as a powerful assistive tool. Instead of manually sifting through code, attempting various payloads, and debugging iteratively, the team turned to Claude. They provided the AI with details about the discovered vulnerability and the target system’s characteristics. Claude then assisted in several crucial ways:

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems
  • Code Generation: It helped in writing initial exploit code snippets tailored to the specific flaw.
  • Debugging: As is common in exploit development, the initial code often contains errors. Claude aided in identifying and suggesting fixes for these bugs, significantly reducing the debugging cycle.
  • Adaptation and Refinement: The AI helped adapt the exploit to various edge cases and environmental nuances, making it more potent and reliable against OpenAI’s specific forum setup. This iterative process, accelerated by Claude, allowed the team to quickly develop a functional exploit capable of executing arbitrary code on the forum’s server.

Gaining Initial Server Access: With the refined exploit in hand, the team successfully executed their code on the community forum’s server. This granted them initial access, a critical foothold within OpenAI’s network. From this vantage point, they could begin internal reconnaissance, looking for further weaknesses and pathways to more sensitive areas.

Discovery of Secondary Vulnerability: Login Tokens and Employee Accounts: During their internal exploration, the Hacktron AI researchers uncovered a second, equally critical vulnerability. This flaw allowed them to harvest or manipulate login tokens associated with OpenAI employee accounts. Login tokens are digital keys that authenticate a user to a system without requiring them to re-enter their password repeatedly. Gaining access to these tokens meant they could impersonate legitimate OpenAI employees.

Accessing Private GitHub Repositories via Codex: The exploitation of employee login tokens provided the ultimate gateway. Specifically, the researchers gained access to an employee’s Codex account. Codex, an AI system developed by OpenAI, is deeply integrated into development workflows, and an employee’s access to it often implies access to a wide array of internal resources. Through this compromised employee account, the team successfully navigated their way into OpenAI’s private GitHub environment. GitHub repositories are the lifeblood of software development, containing source code, intellectual property, proprietary algorithms, and sensitive project documentation. Access to these private repositories represents a severe security breach, even in an authorised test.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

Reporting and Remediation: Within the astonishing timeframe of less than 72 hours from the initial vulnerability discovery, the Hacktron AI team had achieved deep access. True to the spirit of ethical hacking and the bug bounty program, they immediately compiled a comprehensive report detailing their findings, the methods used, and the extent of their access. This report was promptly submitted to OpenAI’s security team. Upon receiving the report, OpenAI acted with commendable speed, verifying the vulnerabilities and implementing patches to secure their systems against these specific exploits. The successful completion of the test and the subsequent remediation led to the recognition and reward of the Hacktron AI team.

Behind the Screens: Technical Deep Dive and Researcher Profiles

The Hacktron AI team’s success was not merely a stroke of luck but a testament to their profound expertise, combined with strategic application of modern AI tools.

The Technical Nuances of the Vulnerabilities

The initial vulnerability in OpenAI’s public community forum, described as being "linked to the way the forum handled certain image files," points towards a class of flaws often found in web applications. These could include:

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems
  • Image Parsing Vulnerabilities: Flaws in image processing libraries (e.g., JPEG, PNG parsers) that can be triggered by specially crafted malicious image files, leading to buffer overflows, memory corruption, or remote code execution.
  • Server-Side Request Forgery (SSRF) via Image URLs: If the forum fetched images from external URLs without proper validation, an attacker could trick the server into making requests to internal network resources.
  • Arbitrary File Upload with Inadequate Validation: Allowing users to upload image files without strictly validating their content or extension, potentially permitting the upload of web shells or malicious scripts disguised as images.
  • Metadata Exploitation: Hidden metadata within image files (EXIF data, XMP) could be crafted to execute commands if the server processed it insecurely.

The specific nature of the flaw allowed the researchers to "run code on the forum’s server," which signifies a remote code execution (RCE) vulnerability – one of the most critical types of security flaws, as it grants attackers direct control over the compromised server.

The secondary weakness, involving "login tokens to access OpenAI employee accounts," suggests several possibilities:

  • Token Mismanagement: Tokens might have been improperly stored, transmitted, or had insufficient expiration policies.
  • Cross-Site Scripting (XSS): If the initial RCE or another flaw allowed XSS, tokens could be stolen from an employee’s browser session.
  • Internal Service Misconfiguration: An internal service accessible from the compromised forum server might have exposed tokens or provided a pathway to request new ones without proper authentication.
  • Employee’s Codex Account: The fact that they gained access to the private GitHub environment "through an employee’s Codex account" indicates that the compromised login tokens were valid for, or could be escalated to, access within OpenAI’s internal development ecosystem, where Codex is likely deeply integrated. This highlights the interconnectedness of systems and how a single point of compromise can cascade into broader access.

Claude: The AI Enabler

It is crucial to clarify that Anthropic’s Claude did not autonomously "hack" OpenAI. Instead, it served as a sophisticated force multiplier for the human researchers. Its role in "writing, debugging, and adapting the exploit" demonstrates the practical application of large language models (LLMs) in complex problem-solving domains like cybersecurity. Claude’s ability to:

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems
  • Generate code in various programming languages: Given a description of a vulnerability, Claude could propose code snippets to exploit it.
  • Identify and correct errors in existing code: Accelerating the debugging process, which is often time-consuming for human developers.
  • Suggest alternative approaches or modifications: Allowing for more robust and stealthy exploits.

This capability significantly reduced the manual effort and time typically required for exploit development, contributing directly to the 72-hour turnaround time. The experiment serves as a stark reminder that AI tools, while powerful, are currently most effective when augmenting human expertise rather than replacing it entirely.

Profiles of the Trailblazing Researchers

The success of this operation rests firmly on the shoulders of the talented individuals at Hacktron AI.

Mohan Pedhapati: As the CTO and co-founder of Hacktron AI, Mohan Pedhapati brings a strong academic and practical foundation to the team. His background in computer science, specifically from RGUKT Nuzvid (2015-2021), provided him with a robust theoretical understanding of systems and networks. Before co-founding Hacktron AI, Pedhapati honed his skills at reputable cybersecurity firms like Cure53 and Electrovolt Infosec. His experience in these roles likely involved extensive penetration testing, vulnerability research, and security auditing for a diverse range of clients, preparing him for high-stakes challenges like the OpenAI bug bounty.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

Harsh Jaiswal: A co-founder of Hacktron AI, Harsh Jaiswal is a highly experienced vulnerability researcher with over a decade in the field. His extensive tenure has seen him contribute to prominent organisations such as Project Discovery, Zomato, and Cure53. Jaiswal’s impressive track record includes identifying and reporting flaws in systems belonging to global tech giants like Apple, PayPal, and GitHub. This deep experience across various platforms and critical systems makes him an invaluable asset, possessing the instinct and technical prowess to uncover deeply embedded vulnerabilities that others might miss. His previous work with GitHub vulnerabilities is particularly relevant, given the ultimate access gained to OpenAI’s private GitHub environment.

Rahul Maini: Completing the trio, Rahul Maini is a skilled vulnerability researcher at Hacktron AI. His experience spans several leading bug bounty platforms and security firms, including Cobalt, Synack Red Team, HackerOne, and Bugcrowd. These platforms are competitive arenas where top security researchers identify and report vulnerabilities for major corporations worldwide. Maini’s active participation and success on these platforms signify his strong practical skills in real-world vulnerability assessment and exploitation. He received his education from Bharati Vidyapeeth, Delhi (2015-2019), providing him with the foundational knowledge to excel in this demanding field.

Hacktron AI: A Rising Force

The cybersecurity startup Hacktron AI, co-founded by Pedhapati and Jaiswal, appears to be positioning itself at the intersection of advanced security research and AI-driven methodologies. Their successful breach of OpenAI using Claude not only validates their approach but also serves as a potent advertisement for their capabilities, demonstrating their innovative use of AI to enhance traditional penetration testing.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

The Economics of Ethical Hacking

The financial figures associated with this breach are equally insightful. The Hacktron AI team reportedly spent less than $3,000 (approximately Rs 2.5 lakh) on AI tokens during the entire test. This relatively modest investment, combined with their expertise, yielded a significant return: a $6,500 (approximately Rs 5.5 lakh) bug bounty from OpenAI. This demonstrates the economic viability of ethical hacking and bug bounty participation for skilled researchers, while also highlighting the cost-effectiveness for companies like OpenAI, who gain invaluable security insights for a fraction of what a full-scale, long-term internal security audit might cost.

OpenAI’s Stance and Swift Remediation

While the original article does not provide direct quotes from OpenAI, the standard operating procedure for leading technology companies involved in bug bounty programs offers a clear picture of their likely response.

OpenAI, a company at the vanguard of artificial intelligence research and development, places immense value on the security and integrity of its systems. Upon receiving the detailed report from Hacktron AI, the company’s security teams would have immediately initiated a verification process. This typically involves replicating the reported vulnerabilities and confirming the extent of the access achieved.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

Following verification, OpenAI would have swiftly moved to remediate the identified flaws. Given the critical nature of the vulnerabilities – particularly the remote code execution on their forum and the access to employee accounts and private GitHub repositories – the remediation would have been prioritised. This would involve patching the affected software, reconfiguring server settings, enhancing input validation, implementing stricter access controls, and potentially rotating compromised credentials or tokens. The rapid resolution is a testament to OpenAI’s robust internal security incident response capabilities.

Furthermore, OpenAI’s payment of the $6,500 bug bounty serves as official acknowledgment and appreciation for the Hacktron AI team’s efforts. It reinforces the company’s commitment to its bug bounty program as a vital component of its overall security strategy. By incentivising external security researchers to responsibly disclose vulnerabilities, OpenAI not only identifies weaknesses that might otherwise go unnoticed but also fosters a collaborative relationship with the broader cybersecurity community. This proactive approach helps to build a more secure foundation for its groundbreaking AI technologies.

Broader Ramifications: The Future of AI in Cybersecurity

The Hacktron AI incident is more than just a successful bug bounty; it’s a microcosm of the evolving challenges and opportunities at the intersection of AI and cybersecurity. Its implications resonate across several critical domains.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

The AI Arms Race: Offensive and Defensive Capabilities

This event vividly illustrates the emerging "AI arms race" in cybersecurity. On one side, AI tools like Claude are proving to be incredibly effective in accelerating offensive operations. Their ability to quickly analyse code, generate exploit payloads, and adapt to different environments gives ethical (and potentially malicious) hackers an unprecedented advantage in speed and efficiency. The human element remains crucial for strategic thinking and decision-making, but AI acts as a powerful tactical assistant.

On the other side, companies like OpenAI are simultaneously investing heavily in AI for defensive purposes. AI-powered intrusion detection systems, anomaly detection, automated vulnerability scanning, and incident response automation are becoming standard. The challenge lies in staying ahead of adversaries who are also leveraging increasingly sophisticated AI tools. This dynamic creates a continuous escalation, where both attackers and defenders must constantly innovate their AI applications.

The Indispensable Role of Bug Bounty Programs

The incident re-emphasises the critical importance of bug bounty programs in modern cybersecurity. No matter how robust an internal security team, an outside perspective often uncovers blind spots. Bug bounty programs provide a structured and incentivised way for companies to tap into a global pool of ethical hacking talent.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems
  • Cost-Effectiveness: As seen with Hacktron AI’s modest expenditure versus the valuable security insights provided, bug bounties can be a highly cost-effective method for security auditing.
  • Continuous Security: Unlike periodic penetration tests, bug bounties can operate continuously, providing an ongoing stream of vulnerability reports.
  • Diverse Skill Sets: Researchers often specialise in niche areas, bringing a variety of perspectives and exploitation techniques that internal teams might lack.
  • Reinforcing Trust: A transparent and well-managed bug bounty program demonstrates a company’s commitment to security and fosters trust with its user base.

For companies at the cutting edge of technology, particularly those developing AI, bug bounties are no longer a luxury but a fundamental necessity.

Securing the AI Frontier

OpenAI, as a leader in artificial general intelligence (AGI) research, faces unique security challenges. Their systems not only contain proprietary AI models and vast datasets but are also increasingly integrated into various applications and services. The potential impact of a breach goes beyond mere data theft; it could involve manipulation of AI models, intellectual property theft of groundbreaking algorithms, or even the misuse of AI capabilities.

  • Model Integrity: Ensuring that AI models are not tampered with or poisoned.
  • Data Security: Protecting the massive datasets used for training and inference.
  • Infrastructure Resilience: Safeguarding the complex computational infrastructure that supports AI development.
  • Supply Chain Security: Verifying the security of third-party tools and components, as seen with the forum vulnerability.

This incident serves as a stark reminder that even the most advanced AI companies must maintain foundational cybersecurity hygiene across all their digital assets, from public-facing forums to internal development environments.

OpenAI Hacked? Meet Indian-origin trio who used Anthropic's Claude to breach its systems

The Human Element in AI-Powered Security

While AI tools are powerful, the Hacktron AI success story firmly places human expertise at the centre. It was the human researchers who identified the initial vulnerability, understood the context, and strategically decided to employ Claude. It was their skill that guided Claude’s output, interpreted its suggestions, and ultimately orchestrated the multi-stage exploit. AI augmented their capabilities, but it did not replace their critical thinking, intuition, or ethical judgment. This highlights that for the foreseeable future, cybersecurity will remain a domain where human intellect, creativity, and ethical responsibility are paramount, with AI serving as an invaluable partner.

In conclusion, the successful, authorised breach of OpenAI by Hacktron AI’s Indian-origin researchers, powered by Anthropic’s Claude, is a landmark event in cybersecurity. It not only showcases the ingenuity of ethical hackers and the efficacy of bug bounty programs but also provides a compelling glimpse into the future of security, where artificial intelligence will play an increasingly pivotal, albeit assistive, role in both defending and challenging digital frontiers. For OpenAI and the broader tech industry, the lesson is clear: robust, multi-layered security strategies, incorporating both human expertise and advanced AI tools, are indispensable in safeguarding the innovations that are shaping our future.