A team of three Indian-origin cybersecurity researchers has demonstrated how advanced AI tools can accelerate the discovery of software vulnerabilities, after using Anthropic’s Claude AI to identify and exploit weaknesses in OpenAI systems.
The researchers — Harsh Jaiswal, Mohan Pedhapati (CTO), and Rahul Maini — work at the cybersecurity firm Hacktron AI. According to their disclosure and reports based on The Wall Street Journal, they chained two critical vulnerabilities in July 2026 to gain access to multiple OpenAI employees’ ChatGPT and Codex accounts, and subsequently reached internal GitHub repositories.
How the Vulnerabilities Were Exploited
The team began investigating after discovering a flaw in Discourse, the third-party software that powers OpenAI’s community forum. The issue involved the processing of certain image files (HEIC/HEIF formats) and a related library vulnerability that could enable remote code execution.
They initially used an earlier version of Claude but made limited progress. After Anthropic released Claude Opus 5, the model helped generate a working exploit within a short time. The researchers then combined this with a separate single sign-on (SSO) identity-related vulnerability at OpenAI.
This chain allowed them to compromise employee accounts and move into internal systems. They demonstrated the access by opening a pull request in an internal repository. The entire process — from initial discovery to proving internal access — took less than 72 hours and cost under $3,000 in AI tokens.
Responsible Disclosure and Bounty
Hacktron AI reported the findings to both OpenAI and Discourse. OpenAI fixed the SSO-related issue in approximately 14 hours. Discourse also addressed the image-processing vulnerability. OpenAI later awarded the team a $6,500 bug bounty (around ₹6.2–6.27 lakh).
The research was conducted under OpenAI’s bug-bounty programme, which provides a safe harbour for security researchers testing the company’s systems.
Broader Implications
The episode has drawn attention to the dual-use nature of powerful AI models. While AI can help defenders find and fix flaws faster, it can also lower the barrier for sophisticated attacks when used by skilled researchers — or potentially by malicious actors.
Security experts note that as AI coding and reasoning capabilities improve, organisations must strengthen monitoring, access controls, and third-party software security, especially for systems connected to employee accounts and internal codebases.
OpenAI has not publicly detailed further comments beyond the fix and bounty payment. The incident adds to ongoing industry discussions about the cybersecurity risks and benefits of frontier AI systems.