Three Indian-origin cybersecurity researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — are at the center of a closely watched Silicon Valley security story after fresh reports on Sept. 21 detailed how their team used Anthropic’s Claude to help breach parts of OpenAI’s infrastructure during authorized vulnerability research. The work was not described as a criminal attack: the researchers reported the weaknesses, OpenAI fixed them, and Hacktron AI received a $6,500 bug-bounty payment.
The trio works with Hacktron AI, a cybersecurity startup based in San Francisco that focuses on applying artificial intelligence to software security testing. The company was founded by security researchers including Jaiswal and Pedhapati and announced a $2.9 million pre-seed financing round earlier in 2026. The OpenAI research has become a particularly visible example of Hacktron’s thesis that advanced AI models can accelerate vulnerability discovery and exploit development that traditionally demanded substantial manual work from highly specialized researchers.
Jaiswal, who helped lead the OpenAI research, is a Hacktron co-founder and vulnerability researcher with more than 10 years of experience in offensive security. Recent profiles say he previously worked in security roles at ProjectDiscovery, Zomato and Cure53 and participated in bug-bounty research through HackerOne. His past work has included identifying vulnerabilities affecting major technology platforms. The OpenAI project also continued a history of collaboration with other members of the Hacktron research team.
Pedhapati is Hacktron’s co-founder and chief technology officer. His background includes web exploitation, source-code review and mobile application security. Before Hacktron, he founded Electrovolt Infosec and worked as a security consultant at Cure53, according to recent biographical reporting. Pedhapati studied computer science at Rajiv Gandhi University of Knowledge Technologies in Nuzvid, India, and has also worked on data-science research. His role in the OpenAI investigation placed him at the intersection of traditional offensive-security techniques and the emerging use of AI coding systems as research assistants.
Maini is a vulnerability researcher whose career has included work with Cobalt, Synack Red Team, HackerOne and Bugcrowd, according to India Today. He has received an AT&T Hall of Fame mention and a Bugcrowd community award and previously studied computer science at Bharati Vidyapeeth in Delhi. NewsBytes similarly identifies him as an experienced member of the bug-bounty community.

The researchers’ path into OpenAI began not with ChatGPT itself but with the company’s public community forum, which runs on the Discourse platform. Reports say the team examined how the forum handled certain image files and identified a vulnerability associated with its image-processing stack. An official Discourse security advisory later documented a high-severity issue involving the libheif image library that could permit remote code execution through image uploads and credited “hacktronai-research” as the reporter. Discourse rated that advisory 8.8 on the CVSS scale and published patched versions.
After gaining control at the forum layer, the researchers identified a separate weakness involving OpenAI’s single sign-on architecture. That second issue allowed the investigation to move beyond the forum and into ChatGPT and Codex accounts belonging to OpenAI employees, according to accounts of the research. One employee’s Codex environment was connected to OpenAI’s GitHub organization, creating a route into a private software repository.
The researchers said they deliberately limited what they did once they demonstrated the access. Rather than examining or downloading sensitive source code, they used an employee’s Codex environment to create a harmless pull request as proof that the access path was real. That distinction is important because the episode has often been described in headlines as researchers “hacking OpenAI,” while the underlying activity was responsible security research conducted with the intention of reporting the vulnerabilities.
Claude’s role was significant but not autonomous. Recent reporting says the Anthropic model assisted the researchers with writing, debugging and adapting exploit code. The human team identified the broader attack path, connected the separate vulnerabilities and decided how far to proceed. That division of labor offers a useful picture of how AI-assisted security work is evolving: models can perform increasingly difficult technical tasks, but skilled researchers still provide targeting decisions, validation, context and judgment.

The entire chain from the research team’s initial investigation to demonstrated repository access took less than 72 hours, according to reports based on Hacktron’s disclosure. The researchers reportedly spent less than $3,000 on AI-token usage during the work. Those figures have attracted attention because exploitation of memory-safety vulnerabilities and multi-stage enterprise attack paths has traditionally required substantial specialist time and expertise.
For U.S. technology companies, the more consequential lesson may be architectural rather than specific to any one AI model. The initial weakness existed in software supporting a public-facing forum, but interconnected authentication allowed the researchers to move toward employee accounts and development infrastructure. That illustrates how identity systems, SaaS integrations and AI agents with access to corporate tools can enlarge the impact of a vulnerability that initially appears isolated.
The incident is also significant for the competitive AI industry. Anthropic’s technology was used by researchers to uncover and exploit weaknesses affecting OpenAI, while OpenAI’s own Codex became part of the route used to demonstrate access to an internal repository. The unusual combination shows why AI laboratories increasingly have to secure not just model endpoints but the full collection of forums, identity systems, cloud services, developer tools and third-party integrations surrounding their employees.
OpenAI subsequently addressed the reported weaknesses, and the researchers received the $6,500 bounty. Discourse separately published its security advisory and patches for the image-processing vulnerability. With the researchers’ identities and backgrounds receiving renewed attention this weekend, the episode has become less a story about three outsiders defeating a major AI company than a demonstration of how quickly a small, experienced security team can amplify its capabilities with frontier AI tools.





Leave a Reply