Three Researchers Used Claude Opus to Breach OpenAI's Internal Repositories for About $3,000
Three Indian security researchers—Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—have disclosed a complete, AI-assisted penetration demonstration against OpenAI: starting from an image upload vulnerability, they chained two flaws to escalate access, ultimately taking over several OpenAI employees' ChatGPT accounts and thereby gaining access to OpenAI's internal code repositories. The whole operation took roughly 72 hours (some say 2 days), with token costs under $3,000.
Confirmed
- The attack was carried out by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—none from prestigious schools or big companies—who pulled it off on pure technical skill.
- The entry point was an image upload vulnerability; by chaining two flaws, the attackers escalated to OpenAI employee account takeover, and were reportedly able to manipulate Codex within those accounts.
- Cost and timeline: token spend under $3,000, taking about 72 hours (m4 and m5 say 2 days; m3 says under 72 hours).
- The disclosure came from security team Hacktron AI; @marcvanderchijs noted the breach date in the disclosure was July 25, 2026.
- The story spread on Reddit and other platforms under headlines like "Three guys with Claude hacked OpenAI," sparking heated discussion.
Unconfirmed
- OpenAI's official response, patching status, and exact bounty amount: @marcvanderchijs claims the bounty was only $6,500, but this cannot be cross-verified with other posts that don't mention a bounty.
- The blog post m1 shared contains only a title and link, with no attack details; full details should follow the Hacktron AI disclosure.
Why it matters
- This is a landmark case of AI being used in real penetration testing/attacks: a competitor model (Claude Opus) breached a top AI company's employee accounts and internal repos at very low cost ($3,000), demonstrating LLMs' real-world capability in chained vulnerability discovery.
- The attackers had no elite-school or big-tech credentials, showing the barrier to such capabilities is dropping fast—a warning for AI companies and enterprise security at large.
2026-09-20 ~ 2026-09-21 · 5 related posts
Primary sources
- [source] Researchers Use Claude Opus 5 to Hijack OpenAI Employee Accounts for Under $3,000 — FinanceYF5 · 2026-09-20
- 3 Indian researchers hacked OpenAI in 2 days for under $3,000 using Opus — FinanceYF5 · 2026-09-21
- [source] 3 researchers hacked OpenAI in 72 hours for under $3,000 using Claude Opus — FinanceYF5 · 2026-09-21
- OpenAI 'hacked by three guys with Claude': blog post makes the rounds — lucky-puke · 2026-09-21
1 near-duplicate retellings: marcvanderchijs