
In July 2026, Hacktron AI’s Harsh Jaiswal, Mohan Pedhapati and Rahul Maini breached OpenAI’s private GitHub repository within 72 hours, chaining a forum flaw to employee accounts.
The team exploited a flaw in Discourse’s image‑processing module that parsed HEIC files via libheif, allowing remote code execution on the community.openai.com server.
Using Claude AI’s code‑generation capabilities, the trio wrote, debugged and ported a binary exploit on a budget of less than ₹23,000 (≈$3,000 in API credits), showcasing how offensive AI can accelerate research.
They demonstrated access by submitting a harmless pull request from a compromised Codex employee account, then reported the findings through Bugcrowd and HackerOne, triggering a prompt patch from OpenAI.
OpenAI’s security team fixed the vulnerability within hours and, in a statement, thanked the researchers for their responsible disclosure, awarding them a $6,500 bug bounty and announcing a full audit of its Discourse integration.
The incident underscores the growing role of generative AI in both offense and defense, as Hacktron’s researchers, none of whom list large university credentials, leveraged Claude to uncover and document a high‑impact flaw.