Three Indian OpenAI researchers, Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, used Anthropic’s Claude during authorised security research that exposed vulnerabilities in OpenAI systems.

SAN FRANCISCO: Three Indian OpenAI researchers have drawn attention across the technology industry after using Anthropic’s Claude to help uncover and exploit security vulnerabilities that ultimately provided a route into OpenAI’s internal software environment.

Harsh Jaiswal, Mohan Pedhapati and Rahul Maini are cybersecurity specialists working with Hacktron AI, a San Francisco-based security startup. Their work was conducted as authorised vulnerability research rather than a malicious attack, and the weaknesses were responsibly disclosed to OpenAI.

The investigation took place in July 2026, but details emerged publicly in September. The team reportedly progressed from finding its initial vulnerability to demonstrating access to an internal OpenAI repository in less than 72 hours.

Who are Harsh Jaiswal, Mohan Pedhapati and Rahul Maini?

Jaiswal, who led the research, is a Hacktron AI co-founder and vulnerability researcher with more than a decade of experience. His previous work includes security roles at ProjectDiscovery, Zomato and Cure53, alongside bug-bounty research involving major technology platforms.

Pedhapati is Hacktron AI’s co-founder and chief technology officer. His background covers web exploitation, source-code review and mobile application security. He previously founded Electrovolt Infosec and worked as a security consultant at Cure53.

Maini is a vulnerability researcher with experience across bug-bounty and penetration-testing platforms including Synack Red Team, HackerOne, Cobalt and Bugcrowd. He studied computer science at Bharati Vidyapeeth in Delhi.

Together, the three Indian OpenAI researchers used AI tools to accelerate work that would traditionally require considerable manual investigation.

How did Claude help them breach OpenAI?

The investigation began with OpenAI’s public community forum, which runs on the third-party Discourse platform.

After identifying a vulnerability, the researchers used Anthropic’s Claude to assist with tasks including developing, debugging and adapting exploit code. They subsequently combined weaknesses that enabled access to OpenAI employee ChatGPT and Codex accounts and demonstrated a path into a private GitHub environment.

Crucially, Claude did not independently decide to attack OpenAI. The researchers identified the vulnerabilities, connected them and determined how the access should be tested.

Reports say the experiment cost less than $3,000 in AI-model tokens. The researchers stopped after demonstrating their access rather than downloading proprietary source code and disclosed their findings. OpenAI subsequently fixed the vulnerabilities and awarded Hacktron AI a $6,500 bug bounty.

The case involving the three Indian OpenAI researchers highlights a wider cybersecurity question: AI models can increasingly help experienced specialists compress complex technical work from potentially lengthy investigations into much shorter periods.

Impact to expect

Security. The research could encourage technology companies to strengthen bug-bounty programmes and internal access controls as increasingly capable AI tools make sophisticated vulnerability research faster and cheaper.