Meet the 3 Indian-Origin Techies Who Used Claude to Hack OpenAI in Under 72 Hours

3 min read
Meet the 3 Indian-Origin Techies Who Used Claude to Hack OpenAI in Under 72 Hours

In a stunning display of modern cybersecurity prowess, three Indian-origin researchers successfully breached the internal systems of artificial intelligence giant OpenAI, exploiting the company’s vulnerabilities using a rival AI chatbot, Anthropic’s Claude.

The masterminds behind the hack are Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini-the core team of the emerging cybersecurity startup, Hacktron AI. Armed with raw curiosity, technical skill, and AI assistance, the trio managed to bypass OpenAI’s defenses in less than 72 hours, highlighting a massive paradox in the AI industry: the very tools being built to revolutionize the world are simultaneously accelerating the capabilities of hackers.

Who Are the Masterminds?

What makes this feat particularly extraordinary is that none of the three researchers hail from globally renowned Ivy League institutions or have traditional “big tech” corporate backgrounds.

  • Harsh Jaiswal: The co-founder of Hacktron AI, Jaiswal boasts over a decade of hands-on experience uncovering critical vulnerabilities. His resume includes stints as a security engineer at Zomato and Vimeo. He is a veteran bug-hunter, having previously exposed critical flaws in platforms run by Apple, PayPal, and GitHub.
  • Rahul Maini: A Computer Science graduate and vulnerability researcher at Hacktron AI, Maini is highly respected in the ethical hacking community. Alongside Jaiswal, he previously spent months in 2021 studying Apple’s infrastructure, eventually finding a misconfiguration that allowed them to run code on Apple’s systems-a discovery that earned them a $50,000 bounty.
  • Mohan Pedhapati: Hailing from Rajamahendravaram in Andhra Pradesh, Pedhapati is the co-founder and CTO of Hacktron AI. Known online as “s1r1us,” he completed his B.Tech from Rajiv Gandhi University of Knowledge Technologies, Nuzvid. Before Hacktron, he founded Electrovolt Infosec and worked as a security consultant, bringing deep expertise in neural networks and infrastructure security.

How Did They Hack OpenAI?

The intrusion, which occurred under OpenAI’s “bug bounty” (ethical hacking) program in late July, began innocuously on a public-facing community forum.

According to the researchers, they were examining OpenAI’s community discussion board, hosted on the Discourse platform, when they discovered a vulnerability in how the forum processed certain image files.

To develop an exploit for this bug, the Hacktron team turned to rival AI models, primarily Anthropic’s newly released Claude Opus 5, alongside OpenAI’s own GPT-5.6 Sol model. The AI tools generated the complex code required to exploit the image vulnerability.

Once inside the forum’s backend, the trio discovered a secondary weakness involving OpenAI’s single sign-on (SSO) system. This critical flaw allowed them to harvest authentication tokens belonging to OpenAI employees’ private ChatGPT and Codex accounts.

With these hijacked credentials, Jaiswal, Maini, and Pedhapati gained access to OpenAI’s highly guarded internal GitHub code repository. To prove their access without causing damage, they made a harmless “pull request” (a suggestion to change code) to the repository.

“The scope of what we could theoretically access was huge,” the researchers noted, stressing that while they had the ability to download the source code, they ethically refrained from doing so.

The Implications: A “Warning Shot” for Big Tech

The Hacktron team immediately reported their findings to Sam Altman’s OpenAI, earning a $6,500 (₹6.22 lakh) bug bounty reward. An OpenAI spokesperson confirmed the incident, stating, “We thank the researchers for contacting us and sharing their findings,” and noted that the vulnerabilities have since been patched.

However, the ease and speed of the hack have sounded massive alarm bells across the cybersecurity landscape.

Pedhapati took to X (formerly Twitter) to criticize OpenAI’s internal security practices. “If the people building these systems truly believe they are powerful enough to create nuclear-level risks… why is that work done through ordinary SAAS products?” he questioned, pointing out the danger of housing critical AI infrastructure behind standard consumer-grade browsers and corporate Slack channels.

Frank Cilluffo, director of the McCrary Institute for Cyber and Critical Infrastructure Security, called the hack a “warning shot.” He cautioned, “If three responsible researchers armed with commercial AI tools could achieve this level of access in days, we have to assume well-resourced foreign intelligence services are pursuing the same targets continuously.”

As AI models become increasingly capable of writing exploit code autonomously, the Hacktron AI breach serves as a stark reminder: in the rapidly escalating AI arms race, defense mechanisms must evolve just as fast as the technology itself.

Get in Touch with India Prime Times

For any updates, queries, or to publish a news article, please reach out to our editorial desk:

Leave a Reply

Your email address will not be published. Required fields are marked *