It doesn’t necessarily take a degree from an IIT or big names on your resume to hack one of the most valuable companies in the world.
Earlier today, a small security research outfit called Hacktron AI revealed that it had chained together two vulnerabilities to compromise OpenAI employees’ ChatGPT and Codex accounts, gain access to OpenAI’s internal code repositories, and even open a pull request inside the company’s private monorepo. Behind the disclosure are three Indian security researchers, Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, who between them have spent close to a decade hacking some of the world’s biggest tech companies, long before AI models like Claude entered the picture.
Here’s a closer look at who they are, and how the OpenAI hack actually played out.

Harsh Jaiswal
Harsh Jaiswal, who goes by the handle rootxharsh online, is one of India’s more recognisable names in bug bounty hunting. He signed up on HackerOne back in January 2016, discovering the world of application security almost by accident, after getting curious about phishing sites while searching for video game cheats as a teenager. That curiosity turned into a career: he went on to work as a security engineer at Zomato and later at video platform Vimeo, while hunting for bugs on the side.
His biggest breakout moment came in January 2021, when he and a close collaborator, Rahul Maini, spent months poking at Apple’s infrastructure, inspired by another team’s high-profile bug bounty haul from the company. The pair found a misconfiguration in a content management system running on Apple’s servers that let them access authenticated files without logging in, eventually letting them plant a webshell and execute code on Apple’s systems. Apple paid them $50,000 for the find, and Forbes later featured Jaiswal for the work. He has since spoken at security conferences including Ekoparty and BSides, and worked with the well-known recon toolkit outfit ProjectDiscovery before co-founding Hacktron AI, where he now serves as Chief Research Officer.
Mohan Pedhapati
Mohan Pedhapati, who uses the handle s1r1us, brings a slightly different pedigree to the team, built around elite capture-the-flag competitions and formal security auditing. He is a graduate in Computer Science of RGUKT Nuzvid (Rajiv Gandhi University of Knowledge Technologies) in Andhra Pradesh. He has represented the competitive hacking team zer0pts, with results that include a top-three finish in the APAC region of BountyCon’s CTF and a qualification for the Google CTF finals. On the disclosure side, he has landed in hall-of-fame lists for Microsoft, Valve, Elastic, and Discord, and once ranked in the top 100 of Google’s Vulnerability Reward Program.
Professionally, Pedhapati worked as a senior security researcher at Cure53, the well-regarded German penetration-testing firm, and founded his own security auditing company, which reportedly grew to around €1.5 million in revenue before he moved on. He has spoken at Black Hat and DEF CON, and been featured by outlets including PortSwigger and Vice for his research. At Hacktron AI, he serves as co-founder and Chief Technology Officer, and has personally driven several of the firm’s highest-profile findings, including a remote code execution bug in PostHog’s production database and an XSS vulnerability in OpenAI’s own Atlas browser months before the OpenAI hack.
Rahul Maini
Rahul Maini, who posts online as iamnoooob, has been one half of the Jaiswal partnership since their early bug-hunting days, and the two have continued working together closely ever since, including as co-authors on much of Hacktron’s published research. He has a BTech in Computer Science from Bharati Vidyapeeth. Beyond the Apple hack that put both their names in the security press, Maini has contributed to the firm’s work on benchmarking how well different AI models, from GLM and DeepSeek to GPT and Claude, perform at finding real-world vulnerabilities, as well as a separate pre-authentication remote code execution flaw the team found in identity software OpenAM.
How The Three Of Them Hacked OpenAI
The team’s OpenAI research began not with ChatGPT itself, but with OpenAI’s public help forum, which runs on the popular forum software Discourse and allows sign-ins through OpenAI’s own account system. The researchers reasoned that if they could compromise the forum, that shared login might open a door into much bigger things.
They found their opening in an image-decoding library called libheif, used by Discourse’s backend when handling iPhone photo formats. Using Anthropic’s Claude models to dig through the library’s code, they discovered a heap buffer overflow that had gone unpatched in Discourse’s server environment, exploitable simply by uploading a crafted image. Claude Opus 4.8 struggled initially to build a reliable exploit, but once Anthropic released Claude Opus 5 mid-investigation, the new model cracked it within hours.
From there, the team used the bug to gain code execution on OpenAI’s actual Discourse server, and because of the shared sign-in, that translated into the ability to take over any employee’s ChatGPT and Codex account. To demonstrate the severity without digging through OpenAI’s actual source code, they took over one employee’s account and asked their connected Codex session to open a harmless pull request inside OpenAI’s internal repository as proof of access, then immediately stopped and filed their report.
OpenAI fixed the underlying issue within about 14 hours and paid the trio a $6,500 bounty, while Discourse shipped its own patch within days. The team has since expanded the research into a broader cybersecurity project tracing the same vulnerable library across other major tech platforms.