• English
  • हिन्दी (Hindi)
  • বাংলা (Bengali)
  • தமிழ் (Tamil)
  • తెలుగు (Telugu)
  • मराठी (Marathi)
  • ગુજરાતી (Gujarati)
  • ಕನ್ನಡ (Kannada)
  • മലയാളം (Malayalam)
  • ਪੰਜਾਬੀ (Punjabi)
  • ଓଡ଼ିଆ (Odia)
  • اردو (Urdu)
  • অসমীয়া (Assamese)
  • भोजपुरी (Bhojpuri)
  • मैथिली (Maithili)
  • डोगरी (Dogri)
  • कोंकणी (Konkani)
  • संस्कृत (Sanskrit)
  • سنڌي (Sindhi)
  • नेपाली (Nepali)
  • සිංහල (Sinhala)
  • Español (Spanish)
  • Français (French)
  • Deutsch (German)
  • Italiano (Italian)
  • Português (Portuguese)
  • Русский (Russian)
  • 日本語 (Japanese)
  • 한국어 (Korean)
  • 中文 简体 (Chinese Simplified)
  • 中文 繁體 (Chinese Traditional)
  • العربية (Arabic)
  • עברית (Hebrew)
  • فارسی (Persian)
  • Türkçe (Turkish)
  • Nederlands (Dutch)
  • Svenska (Swedish)
  • Norsk (Norwegian)
  • Dansk (Danish)
  • Suomi (Finnish)
  • Polski (Polish)
  • Čeština (Czech)
  • Slovenčina (Slovak)
  • Slovenščina (Slovenian)
  • Magyar (Hungarian)
  • Română (Romanian)
  • Български (Bulgarian)
  • Українська (Ukrainian)
  • Ελληνικά (Greek)
  • Hrvatski (Croatian)
  • Српски (Serbian)
  • ไทย (Thai)
  • Tiếng Việt (Vietnamese)
  • Bahasa Indonesia (Indonesian)
  • Bahasa Melayu (Malay)
  • Filipino
  • မြန်မာ (Burmese)
  • ខ្មែរ (Khmer)
  • ລາວ (Lao)
  • Монгол (Mongolian)
  • Қазақ (Kazakh)
  • Oʻzbek (Uzbek)
  • Кыргызча (Kyrgyz)
  • Тоҷикӣ (Tajik)
  • Türkmen (Turkmen)
  • Azərbaycan (Azerbaijani)
  • Հայերեն (Armenian)
  • ქართული (Georgian)
  • Беларуская (Belarusian)
  • Lietuvių (Lithuanian)
  • Latviešu (Latvian)
  • Eesti (Estonian)
  • Íslenska (Icelandic)
  • Gaeilge (Irish)
  • Gàidhlig (Scots Gaelic)
  • Cymraeg (Welsh)
  • Euskara (Basque)
  • Català (Catalan)
  • Galego (Galician)
  • Malti (Maltese)
  • Македонски (Macedonian)
  • Bosanski (Bosnian)
  • Shqip (Albanian)
  • Afrikaans
  • Kiswahili (Swahili)
  • አማርኛ (Amharic)
  • Hausa
  • Igbo
  • Yorùbá (Yoruba)
  • isiZulu (Zulu)
  • isiXhosa (Xhosa)
  • Sesotho
  • Sepedi
  • Shona
  • Soomaali (Somali)
  • Kinyarwanda
  • Chichewa
  • ትግርኛ (Tigrinya)
  • Oromoo (Oromo)
  • Xitsonga (Tsonga)
  • Luganda
  • Akan (Twi)
  • Lëtzebuergesch (Luxembourgish)
  • Frysk (Frisian)
  • Corsu (Corsican)
  • Esperanto
  • Latina (Latin)
  • Basa Jawa (Javanese)
  • Basa Sunda (Sundanese)
  • Cebuano
  • ʻŌlelo Hawaiʻi (Hawaiian)
  • Gagana Samoa (Samoan)
  • Te Reo Māori (Maori)
  • Kreyòl Ayisyen (Haitian Creole)
  • Runasimi (Quechua)
  • Aymar Aru (Aymara)
  • Avañeʼẽ (Guarani)
  • Kurdî (Kurdish)
  • کوردیی ناوەندی (Kurdish Sorani)
  • پښتو (Pashto)
  • ئۇيغۇرچە (Uyghur)
  • ދިވެހި (Dhivehi)
  • ייִדיש (Yiddish)
  • Krio
  • Mizo
  • Manipuri (Meiteilon)
  • Eʋegbe (Ewe)
  • Lingála
  • Bamanankan (Bambara)
  • Hmoob (Hmong)
  • Ilokano

3 Indian-Origin Researchers Used Claude to Breach OpenAI Systems in 72 Hours

Gagan Saxena

Managing Editor

AI-assisted cybersecurity research showing code on a computer screen

Three Indian-origin cybersecurity researchers demonstrated how AI-assisted security research can accelerate the discovery and chaining of vulnerabilities, after using Anthropic’s Claude models during an investigation that reached OpenAI employee accounts and an internal GitHub environment.

The researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of cybersecurity startup Hacktron AI — said the work took less than 72 hours and involved less than $3,000 in AI-model token costs. After the vulnerabilities were reported, OpenAI awarded the researchers a $6,500 bug bounty, according to reporting by The Economic Times based on a Wall Street Journal report.

What Happened?

The research was carried out in July 2026 while the team was examining security weaknesses affecting major AI companies. The investigation began around OpenAI’s public community forum, which uses the third-party Discourse platform.

According to the researchers’ account reported by The Economic Times, the team identified a vulnerability involving image processing and then combined it with a separate identity-related weakness. The chain ultimately allowed them to reach OpenAI employee accounts and an internal GitHub environment.

The researchers said they did not use the access to steal or inspect sensitive source code. Instead, they demonstrated that the access was genuine by creating a harmless pull request in the private repository.

How Claude Helped the Researchers

The team used Anthropic’s Claude models to help with writing, debugging and adapting parts of their security research. Human researchers still identified targets, made decisions and directed the investigation; Claude acted as an accelerator for technical work.

The researchers said the AI-token cost was below $3,000. Reporting also noted that an earlier Claude model was not sufficient for some of the exploit-development work, while a later model helped the team make progress.

From a Public Forum to Internal Access

The reported chain involved several stages rather than a single flaw. The first issue was associated with image processing on the Discourse-powered community forum. The researchers then combined that access with another identity-related weakness.

At a high level, the sequence shows why modern security incidents often involve vulnerability chaining: multiple weaknesses can combine into a much more serious access path.

The reported chain eventually reached employee ChatGPT and Codex accounts and then an internal GitHub environment connected to one of those accounts.

What OpenAI Did After the Disclosure

The researchers reported the findings through bug-bounty channels. The Economic Times reported that OpenAI patched the identity-related issue after notification and awarded the team a $6,500 bounty.

An OpenAI spokesperson said the company thanked the researchers for sharing their findings and that the vulnerability had been resolved, according to the report.

Why This Matters for AI and Cybersecurity

This incident highlights the dual-use nature of modern AI systems. The same capabilities that help developers write and debug software can also help security researchers analyze vulnerabilities and develop proof-of-concept code faster.

  • AI can accelerate technical experimentation.
  • Vulnerability chaining remains important.
  • Identity security is critical.
  • Bug-bounty programmes can improve security through responsible disclosure.
  • AI security requires both offensive testing and defensive controls.

What It Means for the Future of AI Agents

Modern models are increasingly capable of using tools, working with code and completing multi-step tasks. That creates opportunities for defensive security automation, but organizations must carefully control what AI systems can access.

For businesses adopting AI coding assistants or autonomous agents, practical safeguards include least-privilege access, short-lived credentials, strong authentication, isolated development environments, detailed audit logs and human approval for sensitive actions.

Key Takeaways

  • Three Indian-origin researchers at Hacktron AI investigated vulnerabilities affecting OpenAI-related systems.
  • Harsh Jaiswal, Mohan Pedhapati and Rahul Maini said the work took less than 72 hours.
  • The team used Anthropic’s Claude models to accelerate parts of its security research.
  • The reported chain reached OpenAI employee accounts and an internal GitHub environment.
  • The researchers said they used a harmless pull request to demonstrate access rather than inspect sensitive source code.
  • OpenAI awarded the researchers a $6,500 bug bounty after disclosure.

Sources

  1. The Economic Times — 3 Indians breached OpenAI systems using Claude. What happened next?
  2. The Economic Times — 3 Indian-origin researchers used Claude to breach OpenAI systems in 72 hours

FindBrief is summarising publicly reported information. Technical details are kept at a high level and are not instructions for exploiting systems.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to Our Newsletter

    © 2026 FindBrief. All Rights Reserved.

    Which language are you reading?

    Apni pasandida bhasha chunein

    • English
    • हिन्दी (Hindi)
    • বাংলা (Bengali)
    • தமிழ் (Tamil)
    • తెలుగు (Telugu)
    • मराठी (Marathi)
    • ગુજરાતી (Gujarati)
    • ಕನ್ನಡ (Kannada)
    • മലയാളം (Malayalam)
    • ਪੰਜਾਬੀ (Punjabi)
    • ଓଡ଼ିଆ (Odia)
    • اردو (Urdu)
    • অসমীয়া (Assamese)
    • भोजपुरी (Bhojpuri)
    • मैथिली (Maithili)
    • डोगरी (Dogri)
    • कोंकणी (Konkani)
    • संस्कृत (Sanskrit)
    • سنڌي (Sindhi)
    • नेपाली (Nepali)
    • සිංහල (Sinhala)
    • Español (Spanish)
    • Français (French)
    • Deutsch (German)
    • Italiano (Italian)
    • Português (Portuguese)
    • Русский (Russian)
    • 日本語 (Japanese)
    • 한국어 (Korean)
    • 中文 简体 (Chinese Simplified)
    • 中文 繁體 (Chinese Traditional)
    • العربية (Arabic)
    • עברית (Hebrew)
    • فارسی (Persian)
    • Türkçe (Turkish)
    • Nederlands (Dutch)
    • Svenska (Swedish)
    • Norsk (Norwegian)
    • Dansk (Danish)
    • Suomi (Finnish)
    • Polski (Polish)
    • Čeština (Czech)
    • Slovenčina (Slovak)
    • Slovenščina (Slovenian)
    • Magyar (Hungarian)
    • Română (Romanian)
    • Български (Bulgarian)
    • Українська (Ukrainian)
    • Ελληνικά (Greek)
    • Hrvatski (Croatian)
    • Српски (Serbian)
    • ไทย (Thai)
    • Tiếng Việt (Vietnamese)
    • Bahasa Indonesia (Indonesian)
    • Bahasa Melayu (Malay)
    • Filipino
    • မြန်မာ (Burmese)
    • ខ្មែរ (Khmer)
    • ລາວ (Lao)
    • Монгол (Mongolian)
    • Қазақ (Kazakh)
    • Oʻzbek (Uzbek)
    • Кыргызча (Kyrgyz)
    • Тоҷикӣ (Tajik)
    • Türkmen (Turkmen)
    • Azərbaycan (Azerbaijani)
    • Հայերեն (Armenian)
    • ქართული (Georgian)
    • Беларуская (Belarusian)
    • Lietuvių (Lithuanian)
    • Latviešu (Latvian)
    • Eesti (Estonian)
    • Íslenska (Icelandic)
    • Gaeilge (Irish)
    • Gàidhlig (Scots Gaelic)
    • Cymraeg (Welsh)
    • Euskara (Basque)
    • Català (Catalan)
    • Galego (Galician)
    • Malti (Maltese)
    • Македонски (Macedonian)
    • Bosanski (Bosnian)
    • Shqip (Albanian)
    • Afrikaans
    • Kiswahili (Swahili)
    • አማርኛ (Amharic)
    • Hausa
    • Igbo
    • Yorùbá (Yoruba)
    • isiZulu (Zulu)
    • isiXhosa (Xhosa)
    • Sesotho
    • Sepedi
    • Shona
    • Soomaali (Somali)
    • Kinyarwanda
    • Chichewa
    • ትግርኛ (Tigrinya)
    • Oromoo (Oromo)
    • Xitsonga (Tsonga)
    • Luganda
    • Akan (Twi)
    • Lëtzebuergesch (Luxembourgish)
    • Frysk (Frisian)
    • Corsu (Corsican)
    • Esperanto
    • Latina (Latin)
    • Basa Jawa (Javanese)
    • Basa Sunda (Sundanese)
    • Cebuano
    • ʻŌlelo Hawaiʻi (Hawaiian)
    • Gagana Samoa (Samoan)
    • Te Reo Māori (Maori)
    • Kreyòl Ayisyen (Haitian Creole)
    • Runasimi (Quechua)
    • Aymar Aru (Aymara)
    • Avañeʼẽ (Guarani)
    • Kurdî (Kurdish)
    • کوردیی ناوەندی (Kurdish Sorani)
    • پښتو (Pashto)
    • ئۇيغۇرچە (Uyghur)
    • ދިވެހި (Dhivehi)
    • ייִדיש (Yiddish)
    • Krio
    • Mizo
    • Manipuri (Meiteilon)
    • Eʋegbe (Ewe)
    • Lingála
    • Bamanankan (Bambara)
    • Hmoob (Hmong)
    • Ilokano
    Scroll to Top