Telugu Techie Among 3 Indians Who Hacked OpenAI

Three Indian-origin cybersecurity researchers made headlines after using Anthropic’s AI chatbot Claude to help find and exploit security flaws in OpenAI’s systems. One of them, Mohan Pedhapati, is a Telugu techie from Andhra Pradesh.

Mohan Pedhapati, Harsh Jaiswal and Rahul Maini work at cybersecurity startup Hacktron AI. The trio was testing OpenAI’s systems as part of its bug-bounty programme when they discovered security vulnerabilities.

The team reportedly found a flaw in OpenAI’s public community forum that could allow attackers to run code on the server. They used Claude to investigate the vulnerability, write and debug the exploit, and speed up their research.

The researchers later found another weakness involving login tokens that gave them access to OpenAI employee accounts. This eventually provided a path into OpenAI’s private GitHub environment through an employee’s Codex account.

The entire exercise reportedly took less than 72 hours. The researchers spent under USD 3,000 (around Rs 2.5 lakh) on AI tokens during the test.

OpenAI later fixed the vulnerabilities and reportedly paid the team a USD 6,500 (around Rs 5.5 lakh) bug bounty.

Who Are the Three Researchers?

Mohan Pedhapati is the CTO and co-founder of Hacktron AI and a Telugu techie from Andhra Pradesh. He specialises in web security, source-code analysis and mobile application security. He studied computer science at RGUKT Nuzvid in Andhra Pradesh.

Harsh Jaiswal, another Hacktron AI co-founder, has more than 10 years of experience in cybersecurity and vulnerability research. He has previously worked with Project Discovery, Zomato and Cure53 and has found security flaws in platforms including Apple, PayPal and GitHub.

Rahul Maini is a vulnerability researcher at Hacktron AI. He has worked with cybersecurity platforms including Cobalt, Synack, HackerOne and Bugcrowd. He studied computer science at Bharati Vidyapeeth in Delhi.

The incident also highlights how AI tools such as Claude can assist cybersecurity researchers. In this case, Claude helped with technical tasks, while the researchers identified the vulnerabilities, connected them and decided how to use the access they obtained.

X