Cybersecurity

Three Indians Hacked OpenAI With Help From Rival AI Claude

Published

on

Three Indian cybersecurity researchers used Anthropic’s Claude AI models to uncover and demonstrate security weaknesses affecting systems connected to OpenAI, highlighting how advanced artificial intelligence can significantly accelerate vulnerability research.

The researchers—Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of cybersecurity startup Hacktron AI—reported their findings to OpenAI after identifying vulnerabilities that potentially exposed user accounts, connected services and parts of the company’s internal infrastructure.

OpenAI subsequently awarded the researchers a $6,500 bug bounty, equivalent to roughly ₹6.22 lakh.

Who Discovered the OpenAI Security Flaws?

The research team consisted of Harsh Jaiswal, founder of Hacktron AI; AI security researcher Mohan Pedhapati; and computer scientist Rahul Maini.

The researchers said their work was conducted as security research rather than an attempt to misuse the access they discovered.

Their investigation focused on systems connected to OpenAI accounts and ultimately revealed weaknesses involving a third-party platform used by the company.

The incident occurred in July, with the researchers later sharing details of their findings.

How Claude Assisted the Security Research

The team used Anthropic’s Claude models during different stages of the investigation.

Their initial focus was the OpenAI community forum, where ChatGPT and Codex users can communicate and authenticate using OpenAI accounts.

The researchers used Claude Opus 4.8 to examine the code of Discourse, the third-party platform powering the forum. Initial attempts to demonstrate the suspected weakness were unsuccessful.

The researchers then turned to Claude Opus 5, which had been released later that day. According to the team, the newer model was able to help them successfully demonstrate the vulnerability.

By the next day, they said they could access ChatGPT and Codex accounts belonging to some users of the community forum.

Access Extended Beyond OpenAI Accounts

The researchers said the compromised account access could potentially provide pathways into other applications connected to the same identities.

These included services such as email and Slack. Some affected accounts reportedly belonged to OpenAI employees and were linked to internal company services.

According to the researchers, access could potentially expose users’ ChatGPT conversations, including private or sensitive information.

The team subsequently discovered another weakness involving OpenAI’s single sign-on system. They said the issue enabled them to obtain authentication information associated with ChatGPT and Codex accounts belonging to OpenAI employees.

The researchers also reported gaining access to an internal OpenAI code repository.

AI Significantly Reduced the Research Time

One of the most notable aspects of the incident was the amount of time required to complete the research.

Pedhapati estimated that conducting comparable work without Claude could have taken approximately two to three months.

With AI assistance, however, the team said it completed the research in less than three days.

He suggested that newer AI models could potentially reduce the time required even further, with similar research potentially taking less than a day under some circumstances.

The researchers described this capability as a force multiplier, allowing experienced security professionals to perform complex analysis and vulnerability research considerably faster.

Third-Party Software Created an Indirect Attack Path

The research also demonstrates why organizations cannot focus exclusively on vulnerabilities in their own software.

The researchers reportedly gained access through a weakness in Discourse, a third-party service used by OpenAI for its community forum.

This highlights the security risks created by interconnected software ecosystems. An organization may have strong security controls around its primary infrastructure while remaining exposed through an external service, authentication provider or connected application.

Third-party dependencies can therefore become an important part of an organization’s overall attack surface.

AI Could Accelerate Both Defensive and Malicious Research

The incident raises broader questions about the role of advanced AI in cybersecurity.

AI models can help security researchers analyze code, identify weaknesses and automate parts of vulnerability research. However, similar capabilities could also potentially be used by malicious actors to speed up attacks.

The researchers warned that increasingly capable AI systems could make experienced attackers more effective while lowering some of the technical barriers faced by less-skilled threat actors.

This creates a difficult security environment in which defenders may gain new capabilities at the same time as attackers gain access to similar technological advantages.

Connected Accounts Are Becoming a Critical Security Risk

The case demonstrates that compromising a single account or third-party application can have consequences beyond the original system.

Employee identities, single sign-on systems, cloud applications, messaging platforms, source-code repositories and other connected services can create chains of access.

For technology companies handling sensitive user information and proprietary systems, securing these connections is therefore as important as protecting the core application itself.

AI Is Changing the Economics of Security Research

The speed reported by the Hacktron AI researchers illustrates how AI could change the economics of vulnerability discovery.

Tasks that traditionally required substantial manual analysis and experimentation may increasingly be completed in a fraction of the time with capable AI assistance.

For defenders, this could mean faster vulnerability discovery and remediation. For attackers, the same acceleration could potentially shorten the window between identifying a weakness and attempting to exploit it.

As AI models become more capable, organizations may need to reassess how quickly they can detect, investigate and respond to newly discovered vulnerabilities.

Click to comment

Trending

Exit mobile version