Three Indian researchers used Claude to hack into OpenAI in under 72 hours

A three-person Indian startup used Claude to break into OpenAI's internal systems, access employee accounts, and reach its private codebase — all within 72 hours, for under $3,000 in AI tokens.
Three Indian researchers used Claude to hack into OpenAI in under 72 hours
Author
Karan Sethi
Tags

In a rather ironic incident that came to light post a WSJ investigation, OpenAI has now moved to tighten its AI safety guardrails. Just weeks after OpenAI confirmed its AI models going rogue and hacking into Hugging Face, it seems OpenAI itself became the target of a hack, ironically by hackers who used Anthropic’s Claude to achieve the said feat.

Once inside, they got access to the company’s private codebase.

The hack precisely used an image processing vulnerability within OpenAI’s codebase, to get into the models, using Opus 5, just days after its release. The feat was achieved by three-person Indian cybersecurity startup Hacktron.AI, which disclosed that it used Anthropic’s Claude to break into OpenAI’s internal systems in July — gaining access to employee ChatGPT and Codex accounts, reaching the company’s private GitHub monorepo, and opening a pull request inside it, all within 72 hours.

The startup, Hacktron AI, was operating within OpenAI’s bug bounty programme. It reported the vulnerabilities, OpenAI patched them, and paid out a $6,500 bounty. The researchers spent under $3,000 on AI tokens to execute the entire operation.

“We’re just three guys with Claude and Codex subscriptions,” said Mohan Pedhapati, Hacktron’s CTO, in comments to The Wall Street Journal.

Hacktron researchers Jaiswal, Pedhapati, and Maini discovered that HEIC and HEIF image uploads to the forum were being routed through ImageMagick, which uses libheif. The version of libheif running in Discourse’s Docker environment carried a heap buffer overflow vulnerability. That became the initial foothold.

The team ran Claude in an autonomous goal loop against a test Discourse instance to develop a working exploit. By the morning of July 25, the agent had achieved remote code execution. The researchers replicated the attack on OpenAI’s live instance the same day.

From there, the chain widened quickly. OpenAI’s SSO implementation accepted both direct logins and logins via external services without further checks, allowing attackers to take over any OpenAI forum visitor’s account via the Discourse vulnerability. One compromised account used GitHub SSO — which connected directly to OpenAI’s internal code repository.

What was within reach

Authentication tokens obtained through the vulnerability worked on both ChatGPT and OpenAI’s GitHub. Some tokens belonged to OpenAI employees and potentially provided access to its Monorepo — a repository containing proprietary AI software, though not model weights.

The researchers stopped short of exploring sensitive data. To demonstrate access, they opened a pull request inside the private monorepo, filed the disclosure, and stood down.

Claude helped identify missing security backports and develop a working exploit that turned the memory-corruption bug into remote code execution against the forum environment.
Invezz

The researchers did not need to build the exploit from scratch. They needed a target environment, a hypothesis, and an AI model capable of iterating through the technical chain. Claude provided the last part. The cost: a monthly subscription.

Post-hack guardrails

OpenAI has introduced a new framework for tracking and reporting misalignment incidents, with plans to eventually share serious cases with the US government. The company says future disclosures will be more consistent and timely.

Taken together, the week marks a significant moment for OpenAI’s security posture — facing external breaches enabled by a competitor’s AI model on one side, and its own models behaving in unintended ways on the other.

The entire timeline from initial discovery to OpenAI repository access took place in less than 72 hours.

Save time and cost with BIZTRAPPER