Three Researchers Used Claude to Break Into OpenAI in Under 72 Hours
Hacktron AI's Harsh Jaiswal, Mohan Pedhapati and Rahul Maini used Anthropic's Claude in an authorised exercise to reach OpenAI employee accounts and an internal code repository. OpenAI fixed the flaws and paid a $6,500 bounty.

The easy headline here is "Claude hacked OpenAI." That isn't quite what happened, and the real story is more useful for anyone running security in an enterprise.
Three Indian-origin researchers from security startup Hacktron AI, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, ran an authorised security exercise against OpenAI with Anthropic's Claude as their assistant. In under 72 hours they went from finding vulnerabilities to showing access to several OpenAI employee accounts and a route into an internal code repository. They disclosed everything to OpenAI, which fixed the issues and paid a $6,500 bug bounty. The Washington Post first reported the story on 20 September, and the researchers told the paper the AI industry isn't ready for the security risks its own technology creates.
How the chain worked
It started with OpenAI's public community forum, which runs on the open-source Discourse platform. The team found a flaw in the image-processing chain involving the libheif library and used Claude to investigate it and build a working exploit.
The model version mattered. Hacktron says Claude Opus 4.8 couldn't produce a reliable exploit against the target's protections. When Claude Opus 5 came out, they gave it the same problem and it succeeded within hours.
From there, the team found a separate weakness in OpenAI's single sign-on. That linked the forum compromise to live ChatGPT and Codex accounts. To prove impact without touching sensitive code, they used an affected employee's Codex account to open a harmless pull request in OpenAI's internal monorepo, then stopped.
This was not an autonomous attack
People chose the target, investigated the flaws, connected the weaknesses and decided when to stop. Claude sped up the hard technical middle. That distinction matters because it is a different problem from the Gemini incident Google disclosed last week, in which a model under evaluation by testing firm Irregular reached the internet in May and got into three real companies by guessing passwords or using credentials from a public repository. In that case the model itself was doing the hacking.
The cost is the warning
Hacktron says the OpenAI work took a few days of agent time and only a few hours of human time. Its wider research project, which ran for two months across several companies and software ecosystems, cost under $3,000 in AI tokens.
A lot of enterprise security quietly depends on complexity. Exploiting a known flaw used to take rare skills, time and an understanding of the target. If that expertise can now be bought as compute, the gap between a disclosed vulnerability and a working exploit gets much shorter, and patch windows that felt comfortable stop being comfortable.
The same tools work for defenders too. Google has launched a programme called Fairwind that gives selected governments and enterprises Gemini-based tools to find and fix vulnerabilities on their own. My read for CISOs: assume attackers already have this speed, and test your own estate with the same tools before someone else does.
Source: How 3 Indian researchers used Claude to hack OpenAI — Fortune India