Three researchers breached OpenAI‘s software systems in an OpenAI source code hack that earned them a $6,500 bug bounty payout, using rival Anthropic’s Claude AI to carry out the intrusion.
The trio accomplished the breach in under 72 hours, according to Malwarebytes.
The researchers, identified by The Times of India as Harsh Jaiswal, Mohan Pedhapati and Rahul Maini, gained access to OpenAI’s software repository on GitHub, the Wall Street Journal reported.
There they found a portion of OpenAI’s source code named “Monorepo.” Sources told the WSJ that Monorepo is the company’s “secret sauce” that makes its models operate faster.
How the OpenAI Source Code Hack Unfolded
The team used subscriptions to Claude, Anthropic’s AI assistant, and OpenAI’s own Codex coding tool to penetrate the GitHub repository.
“We’re just three guys with Claude and Codex subscriptions,” Pedhapati, of Hacktron AI, told the WSJ.
OpenAI paid out the $6,500 reward through its bug bounty programme, which invites researchers to probe its systems for vulnerabilities in exchange for financial rewards.
The OpenAI source code hack adds to a growing pattern. Both OpenAI and Anthropic have disclosed a string of security breaches in recent months. Both companies have called for safety guardrails to allow AI to be developed at a pace that allows humans to review security threat capabilities before models are released to the public.
AI Tools Accelerate the Search for Vulnerabilities
The speed of the intrusion, under 72 hours from start to finish, points to a broader concern in the security community: AI models are finding cybersecurity holes faster than they can be patched.
In this case, the researchers turned one company’s AI against a rival, using Claude to probe OpenAI’s defences.
OpenAI’s bug bounty programme is designed to channel such activity into disclosed, controlled research rather than malicious exploitation. The $6,500 payment confirms the company accepted the report as a legitimate find.
The incident comes as OpenAI faces heightened scrutiny over its security posture. The company is navigating a potential public listing, which raises the stakes around any disclosure of infrastructure vulnerabilities.
Pedhapati’s firm, Hacktron AI, focuses on AI-assisted security research. The identities of Jaiswal and Maini had not been widely confirmed until The Times of India named all three researchers.
OpenAI has not publicly disputed the WSJ’s account of what Monorepo contains or how the access was obtained.

