AI Exploit Demonstrated by Indian Researchers
Published on:
Share this post

Article Summary
Incident Overview: A three-member team of Indian-origin cybersecurity researchers from Hacktron AI conducted an authorized security test, demonstrating an AI-assisted attack that gained access to parts of OpenAI’s internal systems.
Key Personnel:
- Mohan Pedhapati (CTO)
- Harsh Jaiswal (Researcher)
- Rahul Maini (Researcher)
Methodology: The research utilized Anthropic’s Claude AI model to exploit a vulnerability in a third-party service (OpenAI’s community forum running on Discourse). They initially discovered a flaw related to HEIC/HEIF image processing via the libheif library.
Timeline: The researchers began their investigation on July 23 and reached OpenAI’s internal GitHub environment by July 25, demonstrating access in less than 72 hours.
Findings:
- Access was gained to ChatGPT and Codex accounts of OpenAI employees.
- Researchers revealed the vulnerability by creating a pull request using a compromised account, which did not involve the downloading of sensitive data.
- OpenAI's Monorepo, which contains vital software and algorithms, was accessed, but it is confirmed that no model weights were compromised.
Cybersecurity Implications:
- The incident raises questions about the balance between cybersecurity defenses and the potential of AI to uncover and exploit software vulnerabilities.
- The speed of developing exploits has drastically improved due to AI, compressing what previously took months into days.
Bug Bounty Compensation: OpenAI acknowledged the findings and paid Hacktron a $6,500 bug bounty for reporting the vulnerabilities.
Security Responses:
- OpenAI addressed the issues by fixing the vulnerabilities and revoking affected authentication tokens.
- Discourse also released fixes for the identified vulnerabilities in their forum software.
Concerns Raised:
- There are warnings that AI tools lower the barrier to entry for conducting sophisticated cyberattacks, making it accessible to less experienced individuals.
- Potential cascading risks arise from chaining multiple vulnerabilities (from different systems) to gain broader access.
Statements from Hacktron: The researchers emphasized their small-scale operation and pointed out the disparity in resources between their team and state-backed cyber groups, highlighting their use of generative AI models in their approach.
Broader Industry Context: Following other security breaches (e.g., involving Hugging Face), OpenAI has reassigned a quarter of its engineers to bolster security protocols, indicating a trend towards prioritizing cybersecurity across the tech industry.
AI Tool Utilization: The Hacktron team utilized multiple AI applications, including Claude and OpenAI's own GPT-5.6 Sol, at different stages of the security testing process.
This incident not only showcases the advancements in cybersecurity research through AI tools but also illustrates the emergent threats posed by such technologies in the hands of capable individuals. The emphasis will likely continue to shift towards enhancing security measures across major platforms to mitigate these risks.
Key Terms & Concepts
| Hacktron AI | Cybersecurity startup conducting research |
| OpenAI | Target of cybersecurity exploit |
| Anthropic’s Claude | AI model used in exploit |
| Discourse | Forum software with vulnerability |
| $6,500 | Bug bounty paid to Hacktron |
| July 23, 2026 | Start date of research |
| July 24, 2026 | Release date of Claude Opus 5 |
| July 25, 2026 | Remote code execution achieved |
| Vulnerability in HEIC/HEIF | Type of flaw exploited |
| libheif | Image-processing library involved |
| Codex | OpenAI model used for access |
| Private GitHub environment | Accessed internal software repository |
| Community sign-in tokens |





