Indian-origin reseachers managed to hack OpenAI in less than 72 hours. (Photos: LinkedIn/Harsh Jaiswal, Reuters)

Indian-origin researchers hack OpenAI using Claude, get paid Rs 6 lakh

Indian-origin researchers of an AI cybersecurity startup, Hacktron, hacked into OpenAI's codebase and ChatGPT accounts using Claude AI. After disclosing the flaws that allowed for the breach to happen, OpenAI paid the startup $6,500, or roughly Rs 6.2 lakh.

by · India Today

In Short

  • Indian-origin researchers hack OpenAI using Claude
  • The exploit let employee ChatGPT and Codex accounts be taken over silently
  • They get paid $6,500 (roughly Rs 6.2 lakh)

The world of AI is currently focused on the potential threats that this technology might have to humanity, following incidents of AI agents going rogue. OpenAI, in particular, has disclosed cases where its AI agents have tried to hack into systems. Now, Indian-origin researchers from a cybersecurity startup, Hacktron, have revealed that they were able to hack into OpenAI using Anthropic’s Claude AI.

In a blog post, Hacktron mentioned that the effort was led by Indian-origin researcher Harsh Jaiswal alongside Mohan Pedhapati and Rahul Maini. The three began researching frontier AI companies to find security vulnerabilities.

Hacktron stated that the researchers used Claude AI models to compromise multiple OpenAI employees’ ChatGPT accounts on July 25, 2026. This access could then be used to reach connected services, including GitHub. Then, the researchers were able to use an employee’s Codex account to open a pull request (PR) in OpenAI’s codebase. All of this happened in less than 72 hours.

Hacktron announced the incident on X.

Hacktron stated that it reported the incident immediately to OpenAI. OpenAI fixed the flaw in 14 hours, and later paid a $6,500 bounty, or about Rs 6.2 lakh, to the startup.

How did researchers hack OpenAI?

According to the researchers, they combined a flaw in OpenAI’s identity setup (single-sign on or SSO) with a remote code execution bug in Discourse, the software used for OpenAI’s forum. The issue affected users and OpenAI employees who logged in to OpenAI’s community forum, community.openai.com, through the company’s single sign-on system (SSO) infrastructure.

Discourse was said to have a security flaw when it came to processing photos uploaded from an iPhone. The researchers managed to find a way to exploit this loophole and gain access to the systems via the OpenAI community forum.

This flaw meant ChatGPT and Codex accounts could be taken over without user interaction, and because those accounts could be connected to other tools, the possible scope included GitHub, Slack and email. To avoid accessing sensitive information, the team said it only used the compromised employee account to create proof of access through a pull request and did not inspect internal code.

Hacktron shared the entire timeline of the incident.

Researchers stated that Claude played a central role in the work. They first used Claude Opus 4.8 to inspect the flaw, but it could not create a reliable exploit. After Anthropic released Claude Opus 5, the researchers were able to get an exploit up and running, giving them access. As a cybersecurity firm, Hacktron states that it has access to Anthropic’s Cyber Verification Programme for authorised security research.

Following the disclosure, OpenAI issued a statement."We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions,” the company said.

This incident comes at a time when AI models have only become better at cybersecurity. While the researchers used Claude Opus 5, Anthropic as well as OpenAI have more powerful AI models available to general users – such as Claude Mythos 5.1 and GPT-6 Astra. However, both companies have safeguards in place with such models when it comes to cybersecurity tasks.

Previously, Anthropic had disclosed cases where countries and groups around the world were trying to use Claude for things like mass surveillance and espionage. Though the company had disclosed that it suspended all accounts that were involved in such activities.

On the other hand, we have seen cases, including one where about 700 rogue OpenAI tried to hack into the systems of the US company Hugging Face. Later, OpenAI disclosed that thousands of AI agents used a German wiki site as a message board. Anthropic and Meta have also revealed incidents of rogue AI agents in the past. Such cases have raised fears that AI may pose a threat to humanity, leading to comments from OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei related to slowing down AI development.

- Ends