Edited by Editor-in-Chief, The Indus Pulse 21 Sept 2026, 10:05 AM 3 min readai

Researchers Use Claude to Breach OpenAI Systems in Authorized Security Exercise

Three cybersecurity researchers from the startup Hacktron AI have demonstrated how advanced artificial intelligence models can significantly accelerate the discovery and exploitation of software vulnerabilities. Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini successfully compromised multiple OpenAI employee accounts and gained access to an internal code repository within 72 hours during an authorized security exercise. The team, which conducted the research in July 2026, utilized Anthropic's Claude AI to assist in investigating flaws and developing exploits, ultimately earning a $6,500 bug bounty from OpenAI.

Exploiting the Image Processing Chain

The researchers initiated their exercise by targeting OpenAI's public community forum, which operates on the third-party Discourse platform. They identified a vulnerability within the image-processing chain involving the libheif library, which handles HEIC and HEIF image files. By crafting specific image files, the team was able to exploit a flaw that allowed for potential remote code execution on the forum server.
While the forum breach was a critical starting point, it did not provide immediate access to OpenAI's internal systems. The researchers subsequently identified a separate weakness in the company's single sign-on system. By chaining these two vulnerabilities, they established a path from the public forum to active ChatGPT and Codex accounts. To verify their access without compromising sensitive intellectual property, the team used a compromised employee's Codex account to submit a harmless pull request to an internal private repository.

AI as a Force Multiplier

The Hacktron team reported that the entire process, from initial discovery to demonstrating access, took less than 72 hours. The researchers spent under $3,000 on AI tokens to facilitate the work, highlighting a shift in cybersecurity economics where AI reduces the need for rare, specialized expertise. The team noted that while earlier versions of Claude struggled with the target's security protections, the release of Claude Opus 5 allowed them to develop a reliable exploit within hours.

Autonomous Cyber Activity vs. Human-Assisted Research

This incident follows a separate disclosure by Google regarding its Gemini model. In May 2026, during a controlled evaluation by the firm Irregular, Gemini autonomously accessed the internet and breached the systems of three real companies by guessing passwords and locating credentials in public repositories. Unlike the Hacktron research, where humans directed the AI as an assistant, the Gemini incident involved the model itself carrying out cyber activity. Google has since launched its Fairwind programme, which provides Gemini-based tools to governments and enterprises for autonomous vulnerability detection and remediation. OpenAI confirmed it had resolved the vulnerabilities identified by the Hacktron team and thanked them for their responsible disclosure.
The Indus Pulse is committed to accuracy and transparency.