NEW DELHI, September 19: Three Indian-origin cybersecurity researchers — Harsh Jaiswal, Mohan Pedhapati and Rahul Maini — used advanced AI tools to identify and demonstrate vulnerabilities that gave them access to OpenAI employee accounts and parts of the company’s internal software environment. The research, carried out in July and reported publicly this week, was conducted as authorised security testing, and OpenAI subsequently fixed the vulnerabilities.
Three Researchers Completed Attack Chain in Under 72 Hours
The researchers work with cybersecurity startup Hacktron AI and said the full attack chain took less than 72 hours to develop and demonstrate.
Their work began with a vulnerability affecting OpenAI’s community forum, which uses the Discourse platform. By combining that weakness with an authentication issue, the researchers were able to move from the forum environment to several employee ChatGPT and Codex accounts.
The team stressed that this was responsible security research rather than a malicious intrusion.
Vulnerabilities Exposed Employee Accounts
According to the researchers, the initial vulnerability allowed them to obtain authentication tokens linked to users who had signed into OpenAI’s community platform.
Some of those tokens were associated with OpenAI employees, enabling the researchers to demonstrate access to their ChatGPT and Codex accounts.
The researchers then showed that a compromised account could potentially provide access to connected enterprise services, including OpenAI’s private GitHub environment.
Researchers Reached OpenAI’s Internal GitHub Repository
The team demonstrated the seriousness of the vulnerability by using a compromised employee Codex account to create a pull request inside OpenAI’s private software repository.
However, the researchers said they stopped once they had proved that internal access was possible and did not read or download OpenAI’s private source code or model weights.
OpenAI described the repository access as limited and said there was no evidence that sensitive proprietary material was taken.
Claude Helped Accelerate Security Research
The researchers used Anthropic’s Claude during the initial vulnerability research and exploit-development process.
Their account also indicates that OpenAI’s own AI tools were used during later stages of the authorised testing, meaning Claude did not independently conduct the entire operation. Human researchers remained responsible for directing the investigation and deciding which steps to take.
The case highlights how generative AI can significantly speed up cybersecurity work that previously required larger teams and much more time.
OpenAI Fixes Security Issues
OpenAI confirmed that the researchers reported the vulnerabilities and said it subsequently fixed the security issues.
The company narrowed permissions associated with its Community sign-in system and revoked affected authentication tokens and active sessions.
The underlying vulnerability affecting the Discourse forum software was also reported separately to Discourse and patched.
Researchers Receive $6,500 Bug Bounty
OpenAI awarded Hacktron a $6,500 bug bounty for responsibly disclosing the OpenAI-related vulnerability.
Bug-bounty programmes allow approved security researchers to identify vulnerabilities and report them privately so companies can fix weaknesses before they are exploited maliciously.
The payment and disclosure confirm that the research was handled through a responsible vulnerability-reporting process rather than as an unauthorised theft of OpenAI data.
AI Raises New Cybersecurity Challenges
The experiment has drawn attention because a relatively small team was able to identify, combine and demonstrate potentially serious vulnerabilities within days.
Hacktron researchers said AI tools substantially compressed the time needed to perform complex security research, highlighting how similar technologies could strengthen both cyber defenders and malicious attackers.
The incident therefore raises broader questions for technology companies about securing authentication systems, connected enterprise accounts and third-party services as AI-assisted cybersecurity capabilities become more powerful.
source – The Indian Express / The Wall Street Journal / Financial Express
Supreme News Network




