OpenAI Breached Using Anthropic's Claude: 3 Indian Researchers Earn Bounty
Three Indian cybersecurity researchers at startup Hactron AI—Harsh Jaiswal, Rahul Maini, and Mohan Peddipati—successfully breached OpenAI systems during an authorised security test. Using Anthropic's AI chatbot Claude, the team exploited an image processing vulnerability in OpenAI's Discourse-powered community forum. The breach allowed them to discover another flaw in the login system, obtain authentication tokens, and access employee ChatGPT and Codex accounts, ultimately reaching OpenAI's private software repository. Demonstrating responsible disclosure, the researchers submitted a harmless pull request and reported the vulnerabilities without accessing sensitive data. OpenAI resolved the security issues, disabled the tokens, and awarded the researchers a 6,500 dollar bug bounty for the project.
