Three Indian-origin cybersecurity researchers used Anthropic's Claude to help identify and exploit vulnerabilities in OpenAI's systems, gaining access to employee accounts and a private GitHub environment during an authorised security test conducted under OpenAI's bug bounty programme.
The researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, are associated with cybersecurity startup Hacktron AI. According to reports, the exercise took less than 72 hours from identifying the initial vulnerability to accessing a private OpenAI repository. The team reportedly spent less than $3,000 on AI tokens during the exercise and later received a $6,500 bug bounty from OpenAI.
The researchers initially discovered a vulnerability in OpenAI's public community forum involving the handling of certain image files. The flaw could potentially allow code to be executed on the forum's server. They then used Claude to assist with investigating the vulnerability and developing a working exploit.
Claude was reportedly used for tasks including writing, debugging and adapting exploit code, accelerating parts of the security research process. The researchers remained responsible for connecting the vulnerabilities and deciding how to use the access they obtained.
The team subsequently identified another weakness involving login tokens that could provide access to OpenAI employee accounts. This eventually created a route into the company's private GitHub environment through an employee's Codex account, according to the report.
Jaiswal, a Hacktron AI co-founder, has more than a decade of experience in vulnerability research and has previously worked with ProjectDiscovery, Zomato and security consultancy Cure53. Pedhapati is CTO and co-founder of Hacktron AI, with experience in web exploitation, source-code review and application security. Maini is a vulnerability researcher with previous experience across bug bounty and penetration-testing platforms including HackerOne, Bugcrowd and Synack.
OpenAI has since fixed the reported vulnerabilities. The company publicly operates a bug bounty programme that encourages security researchers acting in good faith to identify and responsibly disclose vulnerabilities in its systems.
The episode comes as increasingly capable AI models are being used for cybersecurity research. OpenAI and Anthropic have both been examining the implications of advanced AI systems for vulnerability discovery and exploitation. Anthropic has separately reported cases in which Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations.
The Hacktron AI exercise highlights how AI coding systems can accelerate parts of vulnerability research, while human researchers continue to determine how individual findings are connected and applied during security testing.
Disclaimer: This article may include information derived from interviews, press releases, public statements, research, company communications and other publicly available or third-party sources. Such material may be summarised, paraphrased or contextualised for journalistic and editorial purposes. All rights in third-party content remain with their respective owners.