Indian Hackers Used Anthropic's Claude To Breach OpenAI Systems, Earned ₹6.27 Lakh Bounty

Indian Hackers Used Anthropic's Claude To Breach OpenAI Systems, Earned ₹6.27 Lakh Bounty

Indian security researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini used Anthropic's Claude AI models to chain two OpenAI flaws and access employee ChatGPT accounts plus an internal GitHub repository. The team spent under $3,000 on AI tokens, demonstrated access through a Codex pull request, and disclosed the issues to OpenAI for a $6,500 bounty too.

Tasneem KanchwalaUpdated: Friday, September 18, 2026, 10:04 AM IST
Indian Hackers Used Anthropic's Claude To Breach OpenAI Systems, Earned ₹6.27 Lakh Bounty

A team of three Indian security researchers used Anthropic's Claude AI models to chain together two software flaws and break into OpenAI's internal systems, ultimately gaining access to employee ChatGPT accounts and the company's internal GitHub code repository.

The researchers and the exploit

According to WSJ, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini spent under $3,000 on AI tokens to combine a heap overflow bug in OpenAI's image decoder with a sign-on vulnerability. The chained exploit gave them access to ChatGPT accounts belonging to OpenAI employees, as well as the company's internal "openai/openai" code repository.

Proof of access, not exploitation

Rather than exploring the internal systems they had broken into, the researchers say they used the compromised access responsibly. They had an employee's connected coding assistant, Codex, open a pull request, inside OpenAI's internal repository purely to demonstrate that the access was real, before disclosing the vulnerabilities to OpenAI.

The report states that the disclosure earned the team a $6,500 (roughly Rs. 6.27 lakh) bounty from OpenAI, though it noted that testing against the community forum used in the initial stage of the attack fell outside the official scope of OpenAI's bug bounty programme.

AI as an attack accelerant

The case, per WSJ, underscores AI's growing role in cybersecurity offence, with one company's model effectively used to penetration-test a rival AI lab at a fraction of the cost and time such an operation would traditionally require. The report noted that the incident is fuelling calls for stronger safeguards across AI companies as models grow more capable of autonomously finding and weaponising software vulnerabilities.