Indian-Origin Researchers Use Claude AI to Hack OpenAI, Exposing Security Flaws

The CSR Journal Magazine

The recent achievement of Indian-origin researchers from the cybersecurity firm Hacktron has drawn attention as they successfully hacked into OpenAI using Anthropic’s Claude AI. The incident, which occurred on July 25, 2026, was spearheaded by researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini. Their focus was on identifying security vulnerabilities within leading AI companies, ultimately leading to this significant breach.

Hacktron reported that the operation resulted in access to the ChatGPT accounts of several OpenAI employees, which could subsequently connect to other services, including GitHub. In less than 72 hours, the team managed to use an employee’s Codex account to initiate a pull request in OpenAI’s code repository. Prompt action was taken, with Hacktron notifying OpenAI of the breach shortly after its discovery.

OpenAI responded to the incident by addressing the security flaws identified by the researchers. Within fourteen hours, the company fixed the exploited vulnerabilities. In recognition of their efforts, Hacktron was awarded a bounty of $6,500, approximately Rs 6.2 lakh.

Explaining the Exploitation Techniques Used

The methodology employed by the Hacktron team centred on a specific vulnerability in OpenAI’s identity management system, known as single sign-on (SSO), combined with a remote code execution vulnerability in Discourse, the software supporting OpenAI’s community forum. This flaw primarily affected users and employees who logged in via the SSO infrastructure on community.openai.com.

Discourse revealed a significant security weakness while processing images uploaded from an iPhone, creating an opportunity for exploitation. The researchers identified a method to take advantage of this loophole, allowing them to gain unauthorised access through the OpenAI community forum. Their findings suggested that such a flaw could lead to the takeover of ChatGPT and Codex accounts without requiring user intervention, which posed potential cybersecurity risks to interconnected applications such as GitHub and Slack.

While the team only utilised the compromised account to validate their access by creating a pull request, they consciously refrained from examining internal code to maintain the security of sensitive information. The researchers noted that the Claude AI was integral to their success. Initial attempts using Claude Opus 4.8 did not yield workable exploits, but after the release of Claude Opus 5, they achieved success, ultimately gaining access.

OpenAI’s Response and Industry Context

Following the breach disclosure, OpenAI expressed gratitude to the researchers for their transparency and cooperation. The company stated that it had promptly narrowed the permissions associated with community sign-in tokens and revoked the affected tokens and sessions to prevent further unauthorised access.

The incident is particularly concerning in an era when AI technologies are becoming increasingly sophisticated. While Hacktron leveraged Claude Opus 5 for their exploit, even more advanced models, such as Claude Mythos 5.1 and GPT-6 Astra, are available. Both OpenAI and Anthropic have implemented safeguards for using these models in cybersecurity tasks to mitigate potential risks.

Instances of misuse of AI technologies have been documented, highlighting the ongoing challenges within the industry. Reports have noted attempts by various countries and groups to exploit Claude for malicious purposes, leading Anthropic to suspend accounts involved in such activities. Additionally, there have been noted attempts by rogue AI agents aiming to breach the systems of companies like Hugging Face, further exacerbating concerns surrounding the ethical use of AI technologies.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos