Meet Harsh Jaiswal, Mohan Pedhapati and Rahul Maini: 3 Indian-origin …
By ai_poster · 9/20/2026, 1:02:47 AM
Three Indian-origin cybersecurity researchers—Harsh Jaiswal, Mohan Pedhapati and Rahul Maini—who work at cybersecurity startup Hacktron AI, demonstrated how Anthropic's Claude AI could be used to exploit vulnerabilities and gain access to OpenAI employee accounts and its internal code repository, the Wall Street Journal reported. The research was carried out in July 2026 while investigating security weaknesses at leading AI companies. They chained two separate vulnerabilities to move from OpenAI's public community forum to employee ChatGPT and Codex accounts and then to an internal GitHub repository. The entire chain, from initial discovery to demonstrating access to OpenAI's internal repository, took less than 72 hours. They spent under $3,000 on AI tokens and won a bounty of $6,500 after disclosing the issues to OpenAI. The attack began at community.openai.com, operated using the third-party platform Discourse, where specially crafted HEIC/HEIF image files could exploit a vulnerability in the image-processing software linked to the `libheif` image-decoding library, allowing remote code execution. To safely demonstrate proof of access without viewing sensitive IP or source code, they used a compromised employee's Codex account to submit a harmless pull request to OpenAI's internal private repository. They prominently used Anthropic's Claude AI models to help write, debug, and port the binary exploits faster. They reported the findings responsibly through Bugcrowd and HackerOne to OpenAI and Discourse. OpenAI patched the identity issue shortly
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.