12 hrs ago
Researchers Used Claude to Reach OpenAI Internal Systems
Three security researchers were testing OpenAI’s systems with permission.
They found a weakness in software used for OpenAI’s online forum.
Anthropic’s Claude helped them write a program that used the weakness.
This let them obtain login tokens connected to some OpenAI employees’ accounts.
One account could reach OpenAI’s private software area.
The researchers made a small proposed documentation change to prove they had access.
They said they did not download private source code or model weights.
OpenAI and Discourse fixed the problems, and OpenAI paid the team a $6,500 reward.
The incident shows that AI can help security researchers find flaws faster, but people still directed the testing.
Hacktron AI researchers Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini used Anthropic’s Claude to exploit a vulnerability in Discourse, which hosted OpenAI’s community forum.
The exploit exposed authentication tokens that reportedly provided access to several OpenAI employees’ ChatGPT and Codex accounts.
One compromised account provided a route into OpenAI’s private GitHub environment and its Monorepo repository.
The researchers said they stopped after demonstrating potential access and did not read or download sensitive source code or model weights.
OpenAI paid Hacktron a $6,500 bounty, revoked affected tokens and sessions, and narrowed permissions; Discourse fixed the forum vulnerability.
- Who
- Hacktron AI researchers Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini; OpenAI; Discourse; and Anthropic’s Claude AI.
- What
- An authorized security test chained a Discourse forum vulnerability with an OpenAI authentication issue, exposing tokens and enabling access to OpenAI accounts and part of its private GitHub environment.
- Where
- The initial flaw was in Discourse software hosting OpenAI’s community forum; the access extended to OpenAI’s GitHub environment and Monorepo repository.
- When
- Testing began on July 23; Claude Opus 5 reportedly produced a working exploit on July 24, and Discourse was notified on July 25.
- Why
- The researchers were participating in OpenAI’s bug-bounty program and testing systems to identify and report security vulnerabilities.
Authorized Security Research
Potential Cybersecurity Risk
Nature of the operation
Authorized Security Research
Hacktron and the reports described the activity as an authorized bug-bounty test conducted under a safe-harbor arrangement, with the researchers stopping after demonstrating potential access.
Potential Cybersecurity Risk
The episode demonstrated that a forum vulnerability and an identity or single-sign-on weakness could be chained to reach sensitive enterprise systems.
Role of artificial intelligence
Authorized Security Research
The researchers said Claude accelerated exploit development and compressed work that might previously have taken much longer, while humans directed the strategy and testing.
Potential Cybersecurity Risk
The incident raises concerns that increasingly capable AI tools could lower the expertise and resources needed to discover and exploit software flaws.
Extent of access
Authorized Security Research
Hacktron said it did not read or download sensitive source code or model weights and used a harmless documentation change as proof of access.
Potential Cybersecurity Risk
The reports said the researchers reached OpenAI’s Monorepo and that one account had access to private-repository metadata and code changes, indicating potentially significant exposure.
Key facts
- Researchers
- Mohan Pedhapati, Harsh Jaiswal, and Rahul Maini of Hacktron AI
- Bounty
- $6,500, reported as approximately ₹6.27 lakh
- Initial flaw
- A vulnerability involving the processing of certain HEIC/HEIF image files in Discourse’s image-processing chain
- AI assistance
- Claude Opus 4.8 initially failed to produce a reliable exploit; the researchers said Claude Opus 5 succeeded within hours
- Potential access
- Authentication tokens, several OpenAI employees’ ChatGPT and Codex accounts, and OpenAI’s private GitHub environment
- Repository
- OpenAI’s Monorepo, which was reported to contain important software and algorithmic material but not model weights
- Remediation
- OpenAI revoked affected tokens and sessions and narrowed Community sign-in permissions; Discourse fixed its vulnerability
Quotes
Mohan Pedhapati
Hacktron AI chief technology officer and member of the research team
“I don’t think we are as strong as Chinese threat actors. We’re just three guys with Claude and Codex subscriptions.”
indianexpress.com
“Work that once required a well-resourced team and months of effort can now be compressed into days.”
indianexpress.com
OpenAI spokesperson
Representative of OpenAI responding to the reported vulnerabilities
“We thank the researchers for contacting us and sharing their findings.”
indianexpress.com





