News Analysis

Mohan Pedhapati and Hacktron’s OpenAI Security Research Using Claude

Harsh Jaiswal led Mohan Pedhapati and Rahul Maini in Hacktron’s July 2026 security research, where the team ethically tested OpenAI systems using Anthropic’s Claude and responsibly reported findings involving ChatGPT, Codex and Discourse.

OpenAI hacked by using Claude
OpenAI hacked by using ClaudeImage: TechSota / Original editorial illustration

Mohan Sri Rama Krishna Pedhapati had already spent years studying browsers, web applications and software vulnerabilities when a July 2026 research project brought his work to a much wider audience. Pedhapati joined with Harsh Jaiswal and Rahul Maini to carry out a three-person Hacktron probe of systems connected to OpenAI. The research was led by Jaiswal, with Pedhapati and Maini helping him. The team used Anthropic’s Claude for part of the technical work, but the researchers decided what to investigate, supplied the technical context, reviewed the model’s output and controlled how far the testing went.

Sometimes the work has been simplified to a simple story of an AI model getting into OpenAI. The published account of Hacktron is a sharper view. In good-faith security testing, the researchers used Claude as a technical tool to tie together separate software vulnerabilities, verify what access was possible, and report the findings. Hacktron said it took less than 72 hours from the initial discovery to proof of access to an internal OpenAI repository.

RGUKT Nuzvid was the beginning of Mohan Pedhapati’s Security Career

Born and raised in Andhra Pradesh, Pedhapati studied computer science at Rajiv Gandhi University of Knowledge Technologies, Nuzvid, after attending a zilla parishad high school near Rajahmundry. At university he began taking part in Capture the Flag competitions, where people solve computer and software problems that have been deliberately made vulnerable. He continued to captain the Invaders team at RGUKT and transitioned from competitive hacking to independent security research.

His public profile lists work in browser and web security with special focus on client-side behavior. Past projects include research into prototype pollution and research into Electron applications such as Discord, Visual Studio Code and Microsoft Teams. He has presented his research at DEF CON, Black Hat, Nullcon and others. Pedhapati also founded Electrovolt Infosec and worked as a senior application security auditor at Cure53.

Pedhapati’s own writing gives a clear picture of how he learned the field. On his hacker roadmap, he prioritizes persistence over credentials and suggests beginners learn through practice instead of solely taking courses. He writes about building knowledge through repeated attempts using CTF competitions, experiments and technical write-ups . That way of working was appropriate to his role in the OpenAI research because experienced researchers were still needed to understand, test and place model output in a larger technical investigation.

Founders of Hacktron Were Three Security Researchers

Zayne Zhang, Mohan Pedhapati, and Harsh Jaiswal founded Hacktron. In May 2026, the company raised a $2.9 million pre-seed round led by Crane Venture Partners with participation from Project Europe, Vercel Ventures, Plug and Play Ventures and Cambridge Enterprise Ventures. The founding team at Hacktron has backgrounds in competitive hacking and security research, and has had prior work featured at DEF CON and Black Hat.

The OpenAI investigation used a different three-person grouping. Harsh Jaiswal is listed as the lead on Hacktron’s research account along with Mohan Pedhapati and Rahul Maini. Zhang was one of the founders of Hacktron, while Jaiswal, Pedhapati and Maini were the researchers named in this particular investigation. By keeping those roles separate we are giving due credit to the people who started the company and the people who did the July research.

The company’s work is a mix of traditional security research and coding models that can examine software, write code and tackle narrowly defined technical challenges. The OpenAI investigation is a concrete example of that approach. Claude did not select the target. Claude did not determine what to do. Hacktron’s researchers gave the model specific problems, reviewed its work and applied their own security knowledge to determine what to test next.

The research began with OpenAI’s community forum.

The team began by examining the community forum of OpenAI which was using Discourse. The researchers traced the image-processing path taken for HEIF files, and discovered it ended at libheif, an image-decoding library. Hacktron’s account says the researchers exploited a bug in that software path to gain remote code execution against the affected forum environment.

Discourse security advisory GHSA-vhm9-85gw-x335 published. The advisory says an upstream libheif issue allowed remote code execution via Discourse image uploads, discovered as CVE-2026-32882. The issue has been rated 8.8 under CVSS by Discourse and was reported by Hacktronai-research. The fix is available in the following releases: 2026.7.0, 2026.6.1, 2026.5.2 and 2026.1.6.

The forum issue was only one part of the research. Hacktron says the team also discovered a vulnerability with OpenAI’s sign-in infrastructure. The researchers were able to link the two discoveries and get into the ChatGPT and Codex accounts of people who used the community forum, including OpenAI employees. The work thus went from a third party forum component to accounts associated with services by OpenAI via a chain of separate findings.

The team had help from Claude with exploit development.

While working on the image-decoder problem, the researchers used Anthropic’s Claude. A research version of Claude Opus 4.8 made progress on the task but failed to produce the working exploit the team needed after several sessions, Hacktron says. Anthropic had released the newer model, Opus 5, as the investigation was ongoing, and the researchers asked it the same question.

Within hours, Hacktron reported that Opus 5 had been a success. The researchers subsequently followed up the outcome in their own research process. The model did some of the coding and exploit work, but Jaiswal, Pedhapati and Maini kept choosing the problem, to check whether the output worked and to decide how the finding related to the rest of the investigation.

That difference is important when you describe the case. Hacktron’s team used Claude in the course of ethical security research. Claude was not an independent actor deciding to go after OpenAI. The researchers issued the instructions and technical data, evaluated the results, and maintained control of the investigation. The Register also described the event as three researchers using Claude to help hack OpenAI employee accounts, rather than Claude executing an autonomous attack.

Team Accesses Employee ChatGPT & Codex Accounts

Hacktron says that after linking the forum discovery with the OpenAI sign-in problem, the researchers were able to access several employee ChatGPT accounts. Another employee had Codex linked to OpenAI’s GitHub organization, which provided the team a way to see if that account could access an internal repository.

The researchers said they did not download OpenAI’s private source code. Instead, they leveraged the employee’s connection to Codex to craft a harmless pull request in OpenAI’s internal monorepo. Hacktron flags proof as pull request 1186742. When the pull request verified the connection to the repository, the researchers stopped that portion of the testing.

This choice restricted the proof to the minimum necessary to prove the access. The team had evidence that the Codex link could connect to the repository without plundering source code or other internal material, technically, it was reachable. It also made the report easier to inspect for the receiving security team, as the researchers were able to point to a specific, harmless action that confirmed the problem.

Response from OpenAI and Discourse to the Reports

Hacktron provided the initial findings to both OpenAI and Discourse and assisted the companies during the remediation process. OpenAI’s published timeline says it confirmed a fix about 14 hours after the first report. Discourse issued its correction shortly thereafter and posted the public advisory July 28.

OpenAI later gave Hacktron a $6,500 bug bounty. The Register reports it took less than 72 hours from discovery to internal repository access and bounty payout. OpenAI told TechCrunch the issues with the researchers had been resolved.

Discourse’s public advisory provided its users with specific patched versions and attributed the report to Hacktron’s research account. The result was a written record of the forum vulnerability, while OpenAI could fix the account-related problem on its own systems. The findings came from researchers . Both organizations resolved the problem in their domain .

Pedhapati’s Previous Work Highlights His Role

The OpenAI research didn’t come at the beginning of Pedhapati’s security career, but after a long period of practice work. His public history includes CTF competitions, prototype pollution, browser security, Electron research, consulting and security auditing. Those experiences predated the coding models Hacktron employed in its investigation.

His roadmap also shows that he has written about how to get into security research through practice. He tells readers to find out the areas they are best at, learn how computer systems work and learn from failed attempts instead of treating them as wasted work. This philosophy is repeated in the OpenAI project, where the previous model, Claude, failed to solve the assigned exploit problem, and the researchers continued with it until a later model provided them with a usable result.

So Pedhapati is best characterized as an experienced security researcher working with a new breed of coding tools. The research was led by Harsh Jaiswal, and Pedhapati and Rahul Maini worked alongside him, while Claude helped with a defined part of the technical work. Then the reports were received by OpenAI and Discourse and their systems were fixed respectively. That story assigns a clear function to each person, company and tool, but does not attribute the entire result to any one of them.