Three Indian cybersecurity researchers used Anthropic’s Claude AI models to identify and exploit security weaknesses that gave them access to OpenAI-linked accounts, connected services and an internal code repository, demonstrating how advanced AI tools can sharply accelerate security research.
The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of cybersecurity startup Hacktron AI, reported their findings to OpenAI. The company later rewarded them with a bounty of $6,500, about ₹6.22 lakh.
Meet the Three Indian Researchers Behind the OpenAI Hack
The three researchers are Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, all associated with cybersecurity startup Hacktron AI.
Jaiswal is the founder of Hacktron AI, Pedhapati is an AI security researcher, and Maini is a computer scientist.
Together, they used Anthropic’s Claude models to identify and exploit security weaknesses affecting OpenAI-linked systems before reporting their findings to the company.
Their work focused on finding weaknesses affecting OpenAI accounts and connected systems. The researchers said their objective was to identify security gaps and report them rather than misuse the access they obtained.
The incident occurred in July, and the researchers later publicly described their findings.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How Did Claude Help Them Find the Flaws?
The researchers used Anthropic’s Claude models as part of their security research.
Their investigation initially focused on OpenAI’s community forum, a space where users of ChatGPT and Codex can discuss the products and sign in using their OpenAI accounts.
The team used Claude Opus 4.8 to identify flaws in the code of Discourse, a third-party service used for the OpenAI community forum. Attempts to exploit the weakness with that model were initially unsuccessful.
A more advanced model, Claude Opus 5, was released that same night. The researchers then used the newer model and were able to exploit the vulnerability.
By the following day, the team could access ChatGPT and Codex accounts belonging to a subset of OpenAI users on the community forum.
What Could the Researchers Access?
Once access to ChatGPT and Codex accounts was obtained, the researchers said they could potentially reach other applications connected to those accounts, including email services and Slack.
Some of the affected accounts belonged to OpenAI employees and were connected to other services, including internal OpenAI email.
Pedhapati said access could expose conversations users were having with ChatGPT, including personal or private material.
The researchers subsequently identified another weakness involving OpenAI’s single sign-on system. That flaw allowed them to obtain authentication information linked to ChatGPT and Codex accounts belonging to OpenAI employees.
The team also gained access to OpenAI’s internal code repository.
How Quickly Was the Research Completed?
The researchers said Claude dramatically reduced the time required to carry out the security research.
Pedhapati estimated that performing the same work alone without Claude could have taken him two to three months. With AI assistance, the Hacktron team completed the work in less than three days.
He said newer models released since the incident could potentially reduce the time further, estimating that similar research might now take less than a day.
The case illustrates what Pedhapati described as a “force multiplier” effect, where increasingly capable AI systems can allow experienced security researchers to complete complex work much faster.
The same acceleration, however, could potentially be available to malicious actors.
Why Did a Third-Party Service Matter?
The researchers did not need to identify a vulnerability directly in OpenAI’s own source code to gain access to user accounts.
Instead, they found a flaw in a third-party service used by OpenAI.
Pedhapati said companies often depend on interconnected software and services, creating security exposure beyond their own core systems. A vulnerability in one external dependency can potentially create a route into the company using it.
Why Does the Incident Matter for AI Security?
The research highlights a broader security concern surrounding increasingly capable AI models. The same technology that helps defensive researchers discover vulnerabilities can potentially make sophisticated hacking techniques easier and faster for malicious actors.
Pedhapati said advanced AI models could make experienced hackers significantly more capable while also lowering barriers for criminals seeking to perform similar work.
Security experts raised concerns about the difficulty of protecting corporate secrets as AI-assisted hacking becomes more capable.
The risks extend beyond ordinary corporate information. Researchers have also raised concerns that powerful AI models themselves, particularly the model weights that make them capable, could become valuable targets for theft.
What Does This Mean for Tech Companies?
The incident shows that a company’s security can depend on more than the strength of its own software. Third-party platforms, sign-in systems, employee accounts and connected applications can all become potential routes into sensitive environments.
For AI companies in particular, rapid improvements in model capabilities may also shorten the time attackers need to identify and exploit weaknesses.
The researchers’ claim that work which might previously have taken months was completed in less than three days illustrates how quickly the economics and speed of security research could change.
The420 Takeaway: “AI Is Not Just Finding Answers, It Is Finding Weaknesses Faster”
The significance of the research goes beyond a single OpenAI vulnerability. Claude helped experienced researchers compress work that could have taken months into days, while the eventual access came through weaknesses involving systems and services surrounding OpenAI rather than simply its core technology.
As AI-assisted security research becomes faster, companies may need to treat third-party dependencies, employee authentication and connected applications as part of the same security perimeter as their own systems.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics