Meet 3 Indian Researchers Who Used Claude to Hack OpenAI in Under 72 Hours

Share

Three Indian cybersecurity researchers made headlines after using Anthropic’s Claude to help uncover security vulnerabilities in OpenAI’s systems. The authorised security test reportedly took less than 72 hours, eventually giving the researchers access to OpenAI employee accounts and a route into the company’s private GitHub environment.

The researchers, Mohan Pedhapati, Harsh Jaiswal and Rahul Maini, are part of Hacktron AI, a cybersecurity startup specialising in vulnerability research. Their work was conducted through OpenAI’s bug-bounty programme, which allows security researchers to identify and report flaws in its systems.

According to a report by The Wall Street Journal, the team spent less than $3,000 (around Rs 2.5 lakh) on AI tokens during the experiment. OpenAI subsequently fixed the vulnerabilities and paid the researchers a $6,500 (around Rs 5.5 lakh) bug bounty.

The incident has drawn attention to how AI tools are changing cybersecurity research. But behind the headlines about Claude helping researchers hack OpenAI are three security specialists with years of experience finding software vulnerabilities.

Who Are the Three Indian Researchers Behind the OpenAI Hack?

The research was led by Harsh Jaiswal, alongside Mohan Pedhapati and Rahul Maini. All three are associated with Hacktron AI and have experience in vulnerability research, penetration testing and bug-bounty programmes.

Their work on OpenAI was not an unauthorised cyberattack. The team was testing the company’s systems under its security programme, looking for weaknesses that could be exploited by attackers.

Here is a closer look at the three researchers and their professional backgrounds.

1. Mohan Pedhapati: Hacktron AI’s CTO and Co-Founder

Mohan Pedhapati is the co-founder and Chief Technology Officer (CTO) of Hacktron AI. His work focuses on web exploitation, source-code review and mobile application security.

Before starting Hacktron AI, Pedhapati founded Electrovolt Infosec and worked as a security consultant at Cure53. He also worked as a data science intern at Eigen Vectors, where he explored recurrent neural networks for speech recognition.

Pedhapati studied computer science at RGUKT Nuzvid in Andhra Pradesh, completing his BTech between 2015 and 2021. Before college, he attended ZPPHS Sampathnagar High School from 2013 to 2015.

His experience across application security and vulnerability research has been central to his work at Hacktron AI.

2. Harsh Jaiswal: The Researcher Who Led the OpenAI Test

Harsh Jaiswal is a co-founder of Hacktron AI and a vulnerability researcher with more than 10 years of experience identifying security flaws.

According to Hacktron, Jaiswal led the research that uncovered the vulnerabilities in OpenAI’s systems, working alongside Pedhapati and Maini.

Before Hacktron AI, he worked as a security engineer and researcher at Project Discovery, Zomato and Cure53. He has also participated in bug-bounty programmes through HackerOne.

Jaiswal’s research has involved identifying vulnerabilities in products and platforms associated with companies such as Apple, PayPal and GitHub. He has also collaborated with Rahul Maini on security research in the past.

His background in vulnerability discovery played a key role in the team’s investigation of OpenAI’s systems.

3. Rahul Maini: A Longtime Bug-Bounty Researcher

Rahul Maini is a vulnerability researcher at Hacktron AI with a background in penetration testing and bug-bounty research.

Before joining Hacktron, Maini worked with organisations and platforms including Cobalt, Synack Red Team, HackerOne and Bugcrowd.

His work has received recognition from the cybersecurity community. Maini has earned an AT&T Hall of Fame mention, a Bugcrowd community award and a first runner-up position at TCS HackQuest 3.0.

He studied computer science at Bharati Vidyapeeth in Delhi, completing his degree between 2015 and 2019.

Maini’s experience in identifying and testing security weaknesses complemented the work of Jaiswal and Pedhapati during the OpenAI investigation.

How Did the Researchers Use Claude to Hack OpenAI?

The investigation began with a vulnerability in OpenAI’s public community forum. The flaw was linked to how the forum handled certain image files, potentially allowing code to be executed on the forum’s server.

The researchers used Claude to help investigate the weakness and develop a working exploit. The AI chatbot assisted with writing, debugging and adapting the exploit, reducing the time needed to work through the technical problem.

The team then identified another weakness involving login tokens that could be used to access OpenAI employee accounts.

That discovery eventually provided a route into OpenAI’s private GitHub environment through an employee’s Codex account.

However, Claude did not independently break into OpenAI’s systems. The researchers identified the vulnerabilities, connected the weaknesses and made the decisions that led to the access they obtained. Claude assisted with parts of the technical work.

Why the OpenAI Security Test Matters

The reported timeline of less than 72 hours highlights how AI tools can help experienced security researchers investigate vulnerabilities and develop exploits more quickly.

The experiment also shows why AI-assisted cybersecurity is not simply about asking a chatbot to hack a company. Identifying useful vulnerabilities, understanding how they interact and determining whether they can expose sensitive systems still require human expertise.

For OpenAI, the research revealed weaknesses that could be addressed through its bug-bounty programme. For the cybersecurity industry, it offered a glimpse of how researchers are incorporating AI into vulnerability discovery and testing.

The work by Jaiswal, Pedhapati and Maini demonstrates how established security research skills and AI assistance can come together during an authorised investigation. Their findings also underline the importance of identifying and fixing vulnerabilities before they can be exploited outside controlled security testing.

Also Read: GTA 6 Online in 2027? Twitch CEO Sees a Bigger Wave After November Launch

Leave the first comment