OpenAI Breach: Telugu-Origin Hacker Wins $6,500 Bounty

Three Indian-origin hackers discovered a vulnerability in OpenAI’s community help forum that could let attackers hijack ChatGPT and Codex accounts. After reporting the flaw, they received a $6,500 bounty from OpenAI. One of the hackers, Pedhapati Mohan Sri Rama Krishna, is a Telugu native and found…

By Felo News Desk · Published

In a recent security incident that highlighted the importance of proactive vulnerability testing, three Indian-origin men uncovered a serious flaw in OpenAI’s community help forum. The flaw, which could allow attackers to take over users’ ChatGPT and Codex accounts, was reported to OpenAI by the trio and subsequently patched. As a result, the hackers received a $6,500 bounty for their discovery.

Who were the hackers?

The team behind the discovery was part of Hacktron AI, a security consulting firm that specializes in identifying and fixing exploitable weaknesses in software. The group consisted of Pedhapati Mohan Sri Rama Krishna, Harsh Jaiswal, and Rahul Maini. Rama Krishna, who is of Telugu origin and hails from Rajamahendravaram, is the founder of Electrovolt Security, a security auditing company based in the same city. According to his LinkedIn profile, he completed high school at Zilla Parishad High School in Sampathnagaram and earned a Bachelor of Technology from Rajiv Gandhi University of Knowledge Technologies in Nuzvid.

Rama Krishna’s background in cybersecurity is extensive. He co‑founded Hacktron AI in 2025, a company that helps organizations discover and remediate vulnerabilities before malicious actors can exploit them. Hacktron’s mission statement emphasizes the importance of securing widely trusted software and expanding research across frontier labs and other internet‑critical systems.

How the vulnerability was discovered

While testing OpenAI’s help forum—accessible at community.openai.com—the trio identified a flaw that could be exploited by any user who logged into the platform. The vulnerability allowed an attacker to hijack the session and gain control over the victim’s ChatGPT and Codex accounts. The hackers documented the issue and notified OpenAI’s security team, providing detailed steps to replicate the exploit.

OpenAI’s response was swift. The company worked closely with the researchers to develop a patch that closed the loophole. Once the fix was deployed, the vulnerability was no longer exploitable, and the security of user accounts was restored.

Reward and impact of the discovery

OpenAI honored the researchers with a $6,500 bounty, a standard practice for companies that rely on external security researchers to identify and fix vulnerabilities. The payment was part of a broader bug bounty program that encourages independent experts to test the safety of OpenAI’s products.

Beyond the monetary reward, the incident underscores the value of responsible disclosure and collaboration between security firms and tech giants. By working together, the researchers helped protect millions of users from potential account takeover attacks.

What comes next?

OpenAI has announced that it will continue to strengthen its security posture by expanding its bug bounty program and investing in additional security audits. Hacktron AI plans to apply its expertise to other high‑profile platforms, aiming to preemptively identify vulnerabilities before they can be exploited.

For the broader cybersecurity community, this case serves as a reminder that even well‑protected platforms can harbor hidden weaknesses. Continuous testing, responsible disclosure, and timely patching remain essential practices for maintaining digital trust.

Key facts

  • Three Indian-origin hackers exposed a critical vulnerability in OpenAI’s help forum.
  • Pedhapati Mohan Sri Rama Krishna, a Telugu native, is a key figure behind the discovery.
  • OpenAI patched the flaw after collaboration and awarded a $6,500 bounty.
  • Bug bounty programs are essential for early detection of security weaknesses.
  • The case reinforces the need for ongoing security audits and responsible disclosure.

Why it matters

The incident demonstrates how third‑party security researchers can play a crucial role in safeguarding major AI platforms, protecting users from potential account takeover attacks.

Frequently asked questions

What is a bug bounty program?

A program that rewards security researchers for finding and responsibly reporting vulnerabilities in software.

How does OpenAI handle discovered vulnerabilities?

OpenAI works with researchers to verify the issue, develop a patch, and then deploy the fix while providing a bounty if applicable.

What does the $6,500 bounty cover?

It compensates the researchers for their time, effort, and the risk involved in discovering and reporting the vulnerability.

Will the vulnerability still exist?

No, the patch has removed the flaw, and the help forum is now secure against the described attack vector.

Sources

  • [1] deccanchronicle.com — originally reported as “Telugu-Origin Man Among Three Who Hacked OpenAI and Found Vulnerabilities”

More from World

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com