Home/Tech/OpenAI Hack: Indian Researchers Used Claude to Find Flaws

OpenAI Hack: Indian Researchers Used Claude to Find Flaws

2 hours ago
3 min read
OpenAI Hack: Indian Researchers Used Claude to Find Flaws - Tech News | Krihaa
Size:
Key Highlights
  • 1Core News and Key FactsThe most striking part of this security story is that one AI company’s model was used by researchers to expose weaknesses inside another AI company’s infrastructure.
  • 2A team of ethical hackers from Hacktron, led by Indian-origin researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, says it chained two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts.According to Hacktron’s account, the researchers discovered the vulnerabilities on July 25 and were able to reach OpenAI’s internal repositories within 72 hours.
  • 3The reported attack path involved OpenAI’s Discourse Cloud environment and weaknesses in its image-upload pipeline involving HEIC and HEIF files.Context and Official StatementsThe researchers say they used Anthropic’s Opus 5 in an autonomous goal loop against their own Discourse Cloud server.
Krihaa News App Logo
Android App4.8 Rating

Get Krihaa News App on Your Mobile

Real-time breaking news alerts, political analysis, and movie reviews on Android.

Fact-Checked by Krihaa Editorial

Core News and Key Facts

The most striking part of this security story is that one AI company’s model was used by researchers to expose weaknesses inside another AI company’s infrastructure. A team of ethical hackers from Hacktron, led by Indian-origin researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, says it chained two critical vulnerabilities to gain access to multiple OpenAI employee ChatGPT accounts.

According to Hacktron’s account, the researchers discovered the vulnerabilities on July 25 and were able to reach OpenAI’s internal repositories within 72 hours. The reported attack path involved OpenAI’s Discourse Cloud environment and weaknesses in its image-upload pipeline involving HEIC and HEIF files.

Context and Official Statements

The researchers say they used Anthropic’s Opus 5 in an autonomous goal loop against their own Discourse Cloud server. The AI agent reportedly generated an exploit script, which the team then used as part of its security research against OpenAI’s environment. The researchers subsequently accessed an employee’s ChatGPT account whose Codex was connected to OpenAI’s GitHub, creating a route toward internal repositories.

Gadgets 360

Hacktron says it disclosed the vulnerabilities to OpenAI, allowing the company to patch the affected systems. OpenAI subsequently awarded the researchers a $6,500 bounty. Hacktron describes its broader work as AI-assisted offensive security, with its platform focused on finding exploitable vulnerabilities and proving their impact.

The report arrives amid wider concerns about autonomous AI agents. The supplied report also references a separate OpenAI internal-model incident involving Hugging Face, but that claim should be treated separately from the Hacktron disclosure rather than presented as part of the same breach.

Krihaa Analysis

The important shift here is from “AI can help hackers” to “AI can actively participate in the vulnerability-discovery chain.” That distinction matters. Traditional security researchers still define the target, constrain the environment and validate the exploit, but an autonomous agent can increasingly handle portions of the repetitive discovery and exploit-development process.

The OpenAI case is particularly revealing because Claude was reportedly used to help test weaknesses in an OpenAI environment. In other words, the competitive AI landscape is also creating a security ecosystem where models from rival companies can become tools for independently auditing one another’s infrastructure.

For Indian technology professionals, the involvement of three Indian-origin researchers is another noteworthy element. More importantly, their work demonstrates a growing intersection between AI engineering and offensive cybersecurity — an area where the ability to reason about code, authentication paths and application behaviour may become as valuable as conventional vulnerability scanning.

The $6,500 bounty also illustrates how responsible disclosure can turn a successful intrusion simulation into a defensive outcome. The researchers did not simply demonstrate access; they reported the flaws, allowing OpenAI to patch them. The larger lesson for companies deploying AI agents is clear: security testing can no longer assume that attackers will rely only on human speed. Defensive teams increasingly need to test against machine-speed discovery and exploitation as well.

Related Topics

Share:

Comments (0)

Join the conversation

Sign in to post comments, like, and reply

Published by

Krihaa News — Hyderabad, Telangana

Krihaa News is committed to accurate, independent reporting. Read our editorial guidelines and corrections policy.

ప్రాయోజిత సమాచారం / Sponsored