00:00A few months ago, three Indian cyber security researchers managed to hack into open AI systems
00:06and got paid $6,500 for it.
00:10But to understand how they managed to do this,
00:13it's worth looking at who these three people actually are.
00:17Meet Hush Jaiswal, Rahul Mahini and Mohan Pedapati.
00:21They work at a small startup called Haktron AI.
00:25The whole thing was an authorized security test
00:28in which the researchers used Claude to help exploit a software flaw,
00:33eventually gaining access to open AI employee accounts.
00:37They used Anthropik's AI chatbot Claude to actually help them during the research.
00:42So Claude was used to hack into open AI.
00:45Hush Jaiswal has been hunting vulnerabilities essentially for years.
00:50His entry into cyber security was almost accidental.
00:53As a teenager, he was looking online for video game cheats
00:56that eventually exposed him to phishing and other security issues.
01:01And in 2016, he signed up on a bug bounty platform.
01:05He started teaching himself cyber security and kept going from there.
01:09Eventually, he was finding vulnerabilities for companies including Zomato and Apple.
01:15And Apple is important to the story because Hush and Rahul,
01:19the other Indian I was referring to, had already worked together before.
01:22In 2021, the two found vulnerabilities in Apple systems and received a $50,000 bounty.
01:29So this wasn't the first time that they had gone looking for this kind of weaknesses
01:34in a major technology company.
01:36Then there's Mohan Pedapati.
01:38His route was very different.
01:40He got into cyber security through Capture the Flag competitions
01:44where students compete by solving security challenges.
01:47He eventually captained his college team, built experience in security research
01:52and later became the co-founder and CTO of Hacktron AI.
01:57So by the time these three started looking at open AI,
02:00they already had years of experience between them.
02:02And this time, they had a new tool.
02:05Claude.
02:05The investigation began on July 23rd
02:08when the team was testing OpenAI's public community forum.
02:12The forum runs on a software called Discourse.
02:15While looking at it, they found a vulnerability
02:17involving the way certain image files were processed.
02:21The researchers started testing the vulnerability
02:24and used Claude to help analyze the problem and then develop code.
02:29The first attempts didn't work.
02:31Then Anthropic released a newer version of Claude
02:34and the researchers tried again.
02:36This time, they managed to get the exploit working
02:39and gained access to the server running that forum.
02:43From there, they found another weakness
02:45and this involved OpenAI's login system.
02:49This gave them access to authentication tokens in OpenAI.
02:53Some of those tokens could be used to actually access OpenAI employee,
02:57ChatGPT and Codex accounts.
02:59And those accounts opened another door.
03:02The researchers eventually reached OpenAI's private software repository
03:06where engineers store and manage the company's code.
03:10Once they proved that they could access the private environment,
03:14they stopped.
03:15They didn't start downloading private code
03:17or looking through sensitive information.
03:19Instead, they created a harmless pull request as proof.
03:23They reported what they'd found to OpenAI.
03:26OpenAI fixed that reported vulnerability,
03:29disabled the affected tokens and sessions.
03:32Hacktron AI, therefore, received $6,500 as a bounty.
03:37The entire chain took less than 72 hours
03:40and the researchers said they spent less than $3,000 on AI tokens
03:43during the project and gained so much more.
03:47After the story came out,
03:48one venture capitalist also pointed out
03:51something else about these three researchers.
03:53That they didn't have the typical Silicon Valley background.
03:56Just years of security research and bug hunting.
03:59And a reminder that sometimes you don't need a huge team.
04:03You just need three curious people who keep asking
04:06what happens if we try this.