By Anjali Sharma
WASHINGTON – Indian-origin researchers from a cybersecurity startup, named Hacktron on Friday said they were able to hack into OpenAI with the help of Anthropic’s Claude chatbot the latest example of security issues at the company as per media reports.
Hacktron in a blog post said that the US-based startup compromised a number of OpenAI employees’ ChatGPT accounts, started a process which enabled them to access their target’s software cache and potentially more than that.
The effort was led by Indian-origin researcher Harsh Jaiswal alongside Mohan Pedhapati and Rahul Maini.
The trio started researching frontier AI companies to find security vulnerabilities.
The blog post read “On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors.”
The team initially began with Claude that can generate code for hackers, to access ChatGPT accounts via an OpenAI staff discussion forum hosted by the Discourse platform. Later on, they made a “pull request” an attempt to change the code in a file – to OpenAI’s service on the GitHub software repository, reports said.
“Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails,” read the blog post.
It noted that the entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours.
Hacktron reported the hack to OpenAI, which later fixed it within 14 hours and paid a $6,500 bounty, or about Rs 6.2 lakh, to the startup.
They carried out the operation as part of the OpenAI programme that rewards ethical hackers for testing its systems.
The researchers claimed that they had access to, but did not download, the code from the GitHub repository.
The team noted that they were largely using OpenAI’s own GPT-5.6 Sol model to carry out the hack despite using Claude initially.
“We thank the researchers for contacting us and sharing their findings”, an OpenAI spokesperson said, and added that the vulnerabilities that had been exploited were addressed by the company.