Meet Harsh Jaiswal, Mohan Pedhapati and Rahul Maini: 3 Indian-origin researchers who used Claude to breach OpenAI systems, won $6,500 bounty

Read the original at Times of India ↗
Times of India · collected 2026-09-18 · by TOI World Desk

Quick Summary

Cybersecurity researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini from Hacktron AI used Anthropic's Claude AI to uncover and exploit vulnerabilities in OpenAI’s systems, gaining access to employee accounts and an internal code repository within 72 hours. They spent less than $3,000 on AI tokens and were awarded a $6,500 bounty by OpenAI for responsibly disclosing their findings. The attack began with exploiting a vulnerability in Discourse's image-processing software at OpenAI’s community forum, allowing them to chain this with other weaknesses to penetrate further into the system.
Written locally by qwen2.5:14b on 2026-09-18, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

In September, cybersecurity researchers at Hacktron AI used Anthropic’s Claude chatbot to breach OpenAI’s internal systems, gaining access to employee accounts and an internal GitHub repository. The researchers discovered a flaw in OpenAI's public help forum hosted by Discourse, which they exploited within 72 hours. They reported the issue immediately, and OpenAI fixed it within 14 hours while paying Hacktron a $6,500 bounty. The incident highlights how quickly AI can be repurposed for cyberattacks, despite efforts to ensure ethical use through bug-hunting programs like this one.

Written for “AI Breach Risks” on 2026-10-05, grounded in this article and the 7 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
17
claim-shaped sentences
Uncertain
18%
3 of 17 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
59.1
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
8
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-18 · how these are computed

Story

📰 AI Breach Risks
Technology · 8 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 18% of its claims. Each row says how that neighbour differs.
Dawn
⚖️ leaning not scored 🔴 0% hedged 0 of 14 📰 publisher trust 77
“Both articles describe the same security breach of OpenAI’s systems using Anthropic's Claude AI, carried out by researchers from Hacktron.”
NBC News
⚖️ leaning not scored 🔴 11% hedged 2 of 19 📰 publisher trust 95
“Both articles describe the same breach of OpenAI's systems by three Indian-origin researchers from Hacktron AI in July 2026.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“Article A describes a breach by AI agents without human approval, while Article B details a legitimate security research effort conducted by humans with company knowledge.”
Semafor
⚖️ Centre 🔴 0% hedged 0 of 4 📰 publisher trust 95
“Both articles describe a specific incident where Indian-origin researchers used Claude AI to breach OpenAI's systems, occurring on July 2026.”
The Guardian
⚖️ Leans right 🔴 13% hedged 2 of 15 📰 publisher trust 68
“Both articles describe a single security incident where researchers used Anthropic’s Claude chatbot to breach OpenAI systems, accessing employee accounts and potentially internal code repositories.”
The Straits Times
⚖️ leaning not scored 🔴 0% hedged 0 of 15 📰 publisher trust 59
“Both articles describe the same security breach conducted by researchers at Hacktron using Claude AI to exploit OpenAI's systems, reported on the same day.”
CBS News
⚖️ leaning not scored 🔴 12% hedged 2 of 16 📰 publisher trust 66
“Both articles describe the same security breach conducted by Hacktron AI researchers using Claude to hack into OpenAI's systems, including employee ChatGPT accounts and accessing internal code repository.”
CBS News
⚖️ leaning not scored 🔴 0% hedged 0 of 3 📰 publisher trust 66
“Both articles describe the identical incident involving Indian-origin researchers using Claude to exploit vulnerabilities in OpenAI's systems, specifically mentioning Hacktron AI and the breach of ChatGPT accounts.”
New York Post
⚖️ leaning not scored 🔴 3% hedged 1 of 30 📰 publisher trust 64
“Article A describes a specific security breach conducted by researchers, while Article B discusses broader industry practices and skepticism towards reported AI security issues.”

Publisher

Times of India · 1716 article(s) · 1 correction(s) detected
Running correction rate · 1 correction(s)
2026-10-04
Tennessee prison chief Frank Strada resigns after Christa Pike's botched execution

Who wrote this

TOI World Desk
717 article(s) here · 1 carrying a prediction
🔮 In August 1994, Don Howard Williams Jr. paid $1.35 million for roughly 1.137 acres of waterfront property beside Maui’s Maalaea Small Boat Harbor.
🔮 Hurst had been regarded as someone who could bring people together, and some residents felt the neighbourhood became more fragmented after her death.
🔮 A $3 purchase at a South Carolina Goodwill store turned into one of the most remarkable thrift-store art discoveries in recent memory.
🔮 The cluster group is in great health, the enthusiasm displayed by everyone is contagious and we are looking forward to new ideas and projects that will continue to enhance the biodiversity throughout the area
🔮 Its rotors could be set to different positions, changing the encryption produced by the device.
🔮 Residents in Maidstone, Kent, have voiced strong opposition to plans to convert a former hotel and wedding venue into a 42-unit co-living development, saying they fear the proposal could put additional pressure on parking, local infrastructure and the character of the neighbourhood.
🔮 Washington, DC, Mayor Muriel Bowser said the redevelopment was also intended to support residents facing housing insecurity.
🔮 After the civil lawsuit triggered renewed attention, he reopened the criminal investigation and said his office would present evidence to a grand jury for possible indictment.
🔮 A federal judge has blocked further construction of border barriers in Texas’ Big Bend region after landowners and local groups warned that the planned infrastructure could cut off their access to the Rio Grande and permanently alter the landscape.
🔮 He thought he would get his hands on some records or perhaps some mid-century furniture.
2026-10-04 · assertive framing · He paid $30 for a painting that sold for $1.35 million
Wire or desk byline, not an individual reporter.
Also by TOI World Desk
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 717 articles by TOI World Desk →

Topics

Anthropic Codex Discourse Indian OpenAI

Subjects

OpenAI ORG · 12× Anthropic ORG · 2× Discourse ORG · 2× Harsh Jaiswal PERSON · 2× Indian NORP · 2× Mohan Pedhapati PERSON · 2× Rahul Maini PERSON · 2× GitHub ORG · 1× Hacktron AI ORG · 1× Wall Street Journal ORG · 1×

Narrative

To safely demonstrate proof of access without viewing sensitive IP or source code, they used a compromised employee's Codex account to submit a harmless pull request to OpenAI's internal private repository They prominently used Anthropic's Claude AI models (spending under $3,000 in API tokens) to help write, debug, and port the binary exploits faster, showcasing how offensive AI capabilities accelerate vulnerability research.
framing: assertive · carried by 1 article(s) · first seen 2026-09-18
🔮 Three Indian-origin cybersecurity researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, demonstrated how Anthropic's Claude AI could be used to exploit vulnerabilities and gain access to OpenAI employee accounts and the company's internal code repository, Wall Street Journal reported.

Claims (17 extracted, 3 hedged)

Three Indian-origin cybersecurity researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, demonstrated how Anthropic's Claude AI could be used to exploit vulnerabilities and gain access to OpenAI employee accounts and the company's internal code repository, Wall Street Journal reported. uncertain
Journal → demonstrate → accounts
The researchers, who work at cybersecurity startup Hacktron AI, carried out the research in July 2026 while investigating security weaknesses at leading AI companies. asserted
who → work → companies
They eventually chained two separate vulnerabilities to move from OpenAI's public community forum to employee ChatGPT and Codex accounts and then to an internal GitHub repository. asserted
They → chain → repository
The researchers said the entire chain, from their initial discovery to demonstrating access to OpenAI's internal repository, took less than 72 hours. asserted
chain → say → hours
They spent under $3,000 on AI tokens and won a bounty of $6,500 after they disclosed the issues to OpenAI. asserted
they → spend → OpenAI
How did the researchers get into OpenAI's systems? asserted
researchers → get → systems
The attack began at community.openai.com, OpenAI's community and help forum, which is operated using the third-party platform Discourse. asserted
which → begin → platform
Hacktron researchers discovered that specially crafted HEIC/HEIF image files could exploit a vulnerability in the image-processing software used by Discourse. uncertain
files → discover → Discourse
The vulnerability was linked to the `libheif` image-decoding library and could allow remote code execution — essentially giving an attacker the ability to execute commands on the affected server. uncertain
vulnerability → link → server
However, gaining control of the forum server alone did not provide direct access to OpenAI's internal code. asserted
gaining → gain → code
To safely demonstrate proof of access without viewing sensitive IP or source code, they used a compromised employee's Codex account to submit a harmless pull request to OpenAI's internal private repository They prominently used Anthropic's Claude AI models (spending under $3,000 in API tokens) to help write, debug, and port the binary exploits faster, showcasing how offensive AI capabilities accelerate vulnerability research. asserted
capabilities → demonstrate → research
Then they reported the findings responsibly through Bugcrowd and HackerOne to OpenAI and Discourse. asserted
they → report → OpenAI
OpenAI patched the identity issue shortly after notification and awarded them a $6,500 bug bounty. asserted
OpenAI → patch → bounty
In a statement to Forbes, OpenAI spokesperson Drew Pusateri said the company thanked the researchers “for contacting us and sharing their findings,” and noted that it had resolved the vulnerability. asserted
it → say → vulnerability
No brand name, colleges or companies' Tech commentator Deedy Das pointed out that none of the three researchers had any big college name on their CVs. asserted
none → point → CVs
"Here are the LinkedIns of the 3 Indian guys who hacked OpenAI with Opus 5 in 2 days for <$3000: Rahul Maini, Mohan Pedhapati and Harsh Jaiswal. asserted
who → hack → 3000
You can just do things," Das posted. asserted
Das → do → things
💬Give feedback
🕘History 🎫Support