Indian Cybersecurity Researchers Use Claude to Expose Critical OpenAI Vulnerabilities

Three Indian cybersecurity researchers at Hacktron AI—Harsh Jaiswal, Mohan Pedhapati and Rahul Maini—used Anthropic’s Claude models while participating in OpenAI’s bug-bounty program, demonstrating how AI can accelerate sophisticated security research. They identified and chained vulnerabilities involving OpenAI’s community forum and login tokens, gaining access to employee ChatGPT accounts and a route into private code repositories and potentially connected services. The researchers said the work was conducted ethically, took less than 72 hours and was reported to OpenAI and the relevant third-party provider, which fixed the issues. OpenAI awarded the team a $6,500 bounty. The case also highlights the researchers’ varied cybersecurity backgrounds, including Pedhapati’s rise from competitive hacking in Andhra Pradesh to professional vulnerability research.
The researchers said the initial entry point involved HEIF or HEIC image uploads to OpenAI’s community forum. Discourse, the third-party forum software, processed the files through a chain of backend tools, creating an avenue for server-side code execution.
The team reportedly spent less than $3,000 on Claude usage during the test, substantially less than the $6,500 bounty OpenAI later awarded them.
The researchers said they demonstrated access without examining sensitive OpenAI data by using an employee’s Codex account to open pull request No. 1186742 in OpenAI’s internal monorepository, openai/openai.
They said the potential reach extended beyond OpenAI’s own systems because users could connect services to ChatGPT and Codex, including GitHub, Slack and email accounts.
Mohan Pedhapati’s earlier career included captaining RGUKT’s competitive hacking team, joining a leading Japanese hacking group and qualifying for a Google hacking-contest final; his 2021 research on prototype pollution ranked fourth in PortSwigger’s list of popular web-hacking techniques.
Publishers
14
Articles
10
Reach
24