New Delhi / San Francisco — In a stunning demonstration of raw skill and the rising capabilities of generative artificial intelligence, three independent cybersecurity researchers from startup Hacktron AI successfully breached OpenAI’s internal systems. What makes the exploit particularly striking is the weaponization of a rival AI: the trio used Anthropic’s Claude to orchestrate the entire attack chain.
The operation, which spanned from initial discovery to full proof of access, took less than 72 hours and cost under $3,000 in AI tokens.
The Hack: Step-by-Step
The security assessment was conducted by Harsh Jaiswal, Rahul Maini, and Mohan Pedhapati. According to industry commentators, none of the researchers come from brand-name colleges or major tech giants, highlighting a triumph of raw curiosity and technical ingenuity over traditional institutional pedigree.
- The Entry Point: The exploit began at OpenAI’s public community help forum, running on a software called Discourse. The researchers uncovered a critical flaw in how the platform processed specific image files, which could let an outsider execute code directly on the server.
- The SSO Vulnerability: Leveraging their initial foothold, the trio targeted a second weakness in OpenAI’s single sign-on (SSO) system. This granted them authentication access to employee ChatGPT and Codex accounts.
- Internal Code Repository Breach: Using one of the compromised accounts, the researchers pushed further into OpenAI’s internal code repository. To verify their access without tampering with sensitive proprietary data, they submitted a single, harmless pull request.
Responsible Disclosure and Bounty
The researchers reported their findings responsibly to OpenAI and walked away with a $6,500 bug bounty. OpenAI has since patched the underlying vulnerabilities.
However, the implications of the breach extend far beyond a single patched bug.
A “Nuclear-Level” Warning for the Tech Industry
Speaking out after the disclosure, Hacktron AI co-founder Mohan Pedhapati raised hard questions regarding the cybersecurity postures of frontier AI laboratories. He questioned why organizations building systems carrying severe existential or systemic risks continue to rely on standard corporate software such as Slack and consumer web browsers.
Security analysts have echoed these concerns. Frank Cilluffo of Auburn University’s McCrary Institute noted that if three independent researchers using commercial AI tools can breach a leading AI firm in a matter of days, well-funded state intelligence agencies are likely performing similar operations continuously and undetected.
Bottom Line
The era of AI hacking AI is officially here. As one AI company’s chatbot is used to break into another’s, security experts emphasize that this incident serves as a critical warning shot for every technology firm: the rules of digital defense must evolve faster than the tools used to break them.