Three Indian Specialists Used Claude to Test OpenAI System Vulnerabilities and Received Reward
Read more
Aaj Tak
www.aajtak.in

Three Indian Specialists Used Claude to Test OpenAI System Vulnerabilities and Received Reward

The field of artificial intelligence is actively discussing the achievements of three Indian cybersecurity specialists. These researchers used Anthropic's Claude chatbot to check for vulnerabilities in the OpenAI system. Notably, they were able to test the security of a major AI platform using the capabilities of artificial intelligence.

The researchers are Harsh Jaiswal, Mohan Pedhapati, and Rahul Mani. All three are affiliated with the cybersecurity company Hacktron AI. They conducted security testing of OpenAI systems as part of the company's Bug Bounty program.

According to the report, the researchers managed to find a vulnerability on the public OpenAI forum. This issue was related to how the system processes certain image files. The specialists discovered that this weakness could be exploited to execute code on the forum's server.

Afterward, they utilized Claude. With the help of the AI, they were able to understand this vulnerability, write the code, debug it, and prepare an exploit. According to the report, this entire process took less than 72 hours.

However, the story did not end with one vulnerability. The researchers continued testing this initial problem and discovered another weakness. Thanks to this, they managed to gain access to some OpenAI employee accounts using login tokens.

Subsequently, the team found a way to penetrate OpenAI's private GitHub environment through an employee account. Thus, by combining various vulnerabilities, the researchers demonstrated how serious a security problem even a small weakness can become.

It is important to understand that Claude did not hack OpenAI on its own. The researchers themselves discovered the vulnerabilities and established connections between them. Claude helped accelerate the coding process, debugging, and other technical tasks.

The team included Harsh Jaiswal, Mohan Pedhapati, and Rahul Mani. Mohan Pedhapati is the CTO and co-founder of Hacktron AI, and Harsh Jaiswal is also a co-founder of the company. Rahul Mani has experience in penetration testing and Bug Bounty programs.

According to the report, during this testing, the team spent less than $3000 USD on AI tokens, equivalent to approximately 2.5 lakh rupees. Subsequently, OpenAI patched these vulnerabilities and paid the researchers a reward of $6500 USD, which is about 6.2 lakh rupees.

This case demonstrates that AI today goes beyond simply answering questions or writing code. Cybersecurity specialists are also using AI tools to accelerate vulnerability research and security testing. However, this also raises an important question: if such AI tools are misused, it could create new challenges for cybersecurity.

Popular