OpenAI Hack: Indian Researchers Used Claude to Find Flaws

- 1Core News and Key FactsThe most striking part of this security story is that one AI company’s model was used by researchers to expose weaknesses inside another AI company’s infrastructure.
- 2A team of ethical hackers from Hacktron, led by Indian-origin researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, says it chained two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts.According to Hacktron’s account, the researchers discovered the vulnerabilities on July 25 and were able to reach OpenAI’s internal repositories within 72 hours.
- 3The reported attack path involved OpenAI’s Discourse Cloud environment and weaknesses in its image-upload pipeline involving HEIC and HEIF files.Context and Official StatementsThe researchers say they used Anthropic’s Opus 5 in an autonomous goal loop against their own Discourse Cloud server.

Get Krihaa News App on Your Mobile
Real-time breaking news alerts, political analysis, and movie reviews on Android.
Core News and Key Facts
The most striking part of this security story is that one AI company’s model was used by researchers to expose weaknesses inside another AI company’s infrastructure. A team of ethical hackers from Hacktron, led by Indian-origin researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, says it chained two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts.
According to Hacktron’s account, the researchers discovered the vulnerabilities on July 25 and were able to reach OpenAI’s internal repositories within 72 hours. The reported attack path involved OpenAI’s Discourse Cloud environment and weaknesses in its image-upload pipeline involving HEIC and HEIF files.
Context and Official Statements
The researchers say they used Anthropic’s Opus 5 in an autonomous goal loop against their own Discourse Cloud server. The AI agent reportedly generated an exploit script, which the team then used as part of its security research against OpenAI’s environment. The researchers subsequently accessed an employee’s ChatGPT account whose Codex was connected to OpenAI’s GitHub, creating a route toward internal repositories.
Gadgets 360
Hacktron says it disclosed the vulnerabilities to OpenAI, allowing the company to patch the affected systems. OpenAI subsequently awarded the researchers a $6,500 bounty. Hacktron describes its broader work as AI-assisted offensive security, with its platform focused on finding exploitable vulnerabilities and proving their impact.
The report arrives amid wider concerns about autonomous AI agents. The supplied report also references a separate OpenAI internal-model incident involving Hugging Face, but that claim should be treated separately from the Hacktron disclosure rather than presented as part of the same breach.
Krihaa Analysis
The important shift here is from “AI can help hackers” to “AI can actively participate in the vulnerability-discovery chain.” That distinction matters. Traditional security researchers still define the target, constrain the environment and validate the exploit, but an autonomous agent can increasingly handle portions of the repetitive discovery and exploit-development process.
The OpenAI case is particularly revealing because Claude was reportedly used to help test weaknesses in an OpenAI environment. In other words, the competitive AI landscape is also creating a security ecosystem where models from rival companies can become tools for independently auditing one another’s infrastructure.
For Indian technology professionals, the involvement of three Indian-origin researchers is another noteworthy element. More importantly, their work demonstrates a growing intersection between AI engineering and offensive cybersecurity — an area where the ability to reason about code, authentication paths and application behaviour may become as valuable as conventional vulnerability scanning.
The $6,500 bounty also illustrates how responsible disclosure can turn a successful intrusion simulation into a defensive outcome. The researchers did not simply demonstrate access; they reported the flaws, allowing OpenAI to patch them. The larger lesson for companies deploying AI agents is clear: security testing can no longer assume that attackers will rely only on human speed. Defensive teams increasingly need to test against machine-speed discovery and exploitation as well.
Related Topics
Comments (0)
Join the conversation
Sign in to post comments, like, and reply
Suggested Stories in Tech

Mac mini M6 Benchmark: Multi-Core Performance Surges
Mac mini M6 benchmark results show 4,610 single-core and 20,676 multi-core points, highlighting stronger sustained performance from Apple’s new 12-core desktop chip.

Logitech MX Keypad: AI Control Centre Launches at Rs 15,999
Logitech MX Keypad launches in India at Rs 15,999 with nine customisable LCD keys, AI workflow support and three months of GitHub Copilot Pro+ included.
Will OpenAI and Jony Ive’s Venture Remain Nameless ?
OpenAI and Jony Ive’s joint venture will remain without a public name for the time being, after a U.S. court upheld the temporary restraining order (TRO) preven...
Published by
Krihaa News — Hyderabad, Telangana
Krihaa News is committed to accurate, independent reporting. Read our editorial guidelines and corrections policy.




