OpenAI Gets Hacked by Indian-Origin Ethical Hackers Using Anthropic’s Claude

Hacktron’s team was able to gain access to the ChatGPT accounts of multiple OpenAI employees.

Advertisement
Written by Dhruv Raghav, Edited by Rohan Pal | Updated: 18 September 2026 18:19 IST
Highlights
  • Hackers used Anthropic’s Opus 5 model to hack OpenAI
  • Hacktron’s exploited two vulnerabilities two hack OpenAI
  • OpenAI’s internal AI model recently hacked Hugging Face

OpenAI has since fixed the vulnerabilities

Photo Credit: Unsplash/ Keepcoding

OpenAI recently revealed how its internal model bypassed security measures to escape its isolated testing environment and attacked another AI firm, Hugging Face. The “rouge” AI agent hacked the firm's security system and compromised data of a customer earlier this year, in July. The internal model IM1, which is comparable to OpenAI's GPT 5.6 model, gained unauthorised access to the public internet without even being prompted to do so. Now, a team of ethical hackers, led by three Indian-origin researchers, claims that they were able to hack into OpenAI's internal repositories by exploiting two “critical” vulnerabilities, with the help of Anthropic's AI agent.

OpenAI Rewards Hackers for Reporting the Vulnerabilities

A team of ethical hackers from the research firm Hacktron, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, revealed in a blog post that they hacked OpenAI for research. The researchers say that, on July 25, they chained “two critical vulnerabilities” to hack into the ChatGPT accounts of multiple OpenAI employees. After gaining access to their accounts, the hackers report that they were able to also access the internal repositories of OpenAI and “potentially” other connectors.

Advertisement

Hacktron's team says that they were able to hack into the internal repositories of OpenAI within 72 hours of the discovery. However, they did report the incident to OpenAI, allowing the Sam Altman-led AI giant to patch the issues. OpenAI uses Discourse for its community forum. Hacktron's team, led by the three Indian-origin hackers, was able to find security issues in Discourse's image-upload pipeline, where HEIC and HEIF files “followed an unusual path”.

After the release of Anthropic's Opus 5 AI model, Hacktron's team created an exploit and placed Claude in an autonomous goal loop against their own Discourse Cloud server. The AI agent managed to generate an exploit script, using which the ethical hackers were able to gain remote access to OpenAI's Discourse Cloud instance.

Advertisement

Hacktron's team was then able to take over the ChatGPT account of an employee, whose Codex was connected to OpenAI's GitHub. After reporting the incident to OpenAI, the AI giant rewarded a sum of $6,500 (roughly Rs. 6,24,000) as a bounty to the ethical hackers after patching the vulnerabilities that allowed them to hack into its repositories.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: OpenAI, Opus 5, Anthropic, Hacktron
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 Series Price Hike Not Happening Anytime Soon
  2. Lava Bold N4 Pro 5G Launched in India With 6,000mAh Battery
  3. Samsung's Android 17-Based One UI 9 Update Rolling Out to Older Galaxy Phones, Tabs
  4. OnePlus 13s Gets a New 16GB RAM Option in India at This Price
  5. Apple 18 Pro Max Manages Full Charge Faster Than iPhone 17 Pro Max, Video Reveals
  6. OnePlus 16 Complete Specifications Leaked by Tipster Months Ahead of Launch
  7. iPhone 18 Pro, iPhone 18 Pro Max Sale: India Price, Offers, and More
  1. TRAI Adds New Rules for Spam Calls, Automated Calls and A2P Communications
  2. Meta Muse AI Agent Arrives on Mac With Support for Complex Tasks: What to Know
  3. WhatsApp Could Bring New Theme Categories and Wallpapers to Android
  4. Mivi One 5G Camera Details Revealed, Mivi Care+ Support Teased Ahead of Launch
  5. OpenAI Gets Hacked by Indian-Origin Ethical Hackers Using Anthropic’s Claude
  6. OpenAI Announces Astra for Law With GPT-6 Astra, Legal Search Index and Specialist Plugins
  7. Google Gemini Live Could Get an Ephemeral Video Mode for More Private AI Sessions
  8. Apple Pay Could Launch in India Next Month With Axis Bank Credit Cards, Report Claims
  9. Samsung Gallery Adds Google Photos Integration Ahead of OneDrive Sync Ending: How It Works
  10. BenQ Showcases New iScreenBar and ScreenBar Max Desk Lighting Systems at InfoComm 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.