Technology
The Indian Express

OpenAI hack: 3 Indian-origin researchers used Anthropic’s Claude to breach systems

Source Entity

The Indian Express

September 19, 2026
OpenAI hack: 3 Indian-origin researchers used Anthropic’s Claude to breach systems

Researchers from Hacktron AI used Anthropic's Claude to exploit vulnerabilities in OpenAI's systems, successfully accessing employee accounts and private GitHub repositories. The ethical hack was reported to OpenAI, which has since patched the security flaws and rewarded the team.

The Intersection of AI and Cybersecurity: An Ethical Breach

In a landmark demonstration of the evolving landscape of digital security, a three-member research team from the cybersecurity startup Hacktron AI—comprising Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini—has successfully performed an ethical hack on OpenAI’s internal systems. This incident marks a significant milestone in how generative AI models are being leveraged not just for creative tasks, but as sophisticated tools for identifying and exploiting complex software vulnerabilities.

The Mechanics of the Attack

The researchers utilized Anthropic’s Claude chatbot to assist in the identification and exploitation of vulnerabilities within third-party services used by OpenAI. By leveraging Claude’s code-generation capabilities, the team successfully compromised several OpenAI employees' ChatGPT and Codex accounts. The attack chain originated from an OpenAI staff discussion forum hosted on the Discourse platform, which eventually allowed the researchers to pivot into OpenAI’s private GitHub environment.

The Scope of the Vulnerability

According to the researchers, the breach was not merely superficial. By chaining together two critical vulnerabilities, the team gained unauthorized access to internal software caches. They notably performed a harmless “pull request” to demonstrate their control over the repository. While the potential scope for data exfiltration was vast, the team explicitly stated they did not read or download any of OpenAI’s private source code, maintaining the ethical boundaries of their research.

Ethical Disclosure and Institutional Response

Crucially, this operation was conducted under the auspices of OpenAI’s bug-bounty program. Upon discovering the flaws, Hacktron AI immediately reported their findings to OpenAI. In response, OpenAI acknowledged the security gaps, resolved the issues, and awarded the researchers $6,500 for their contribution to the platform's safety. This collaborative approach underscores the industry standard of 'white-hat' hacking, where security professionals partner with tech giants to preemptively close vulnerabilities.

Broader Implications for AI Security

The incident serves as a stark reminder of the 'strange new state' of AI security, where AI models are increasingly used to automate and scale cyberattacks. As companies like OpenAI and Anthropic continue to lead the AI race, the pressure to maintain robust security protocols is intensifying. This event highlights that even the most advanced AI companies are susceptible to vulnerabilities in their third-party integrations, emphasizing the need for rigorous supply-chain security.

Future Trends in AI-Assisted Threats

Looking forward, the use of AI tools like Claude to conduct security research is likely to become a double-edged sword. While it empowers security researchers to find flaws faster, it also lowers the barrier for malicious actors to conduct sophisticated operations. The industry must now grapple with the reality that defensive security teams will need to employ AI-driven monitoring and detection systems to counter the very models that facilitate these complex, multi-stage digital breaches.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to The Indian Express