(Advertisement)

top ad mobile advertisement
news3h ago

Turns out an OpenAI model breached Hugging Face

OpenAI has disclosed that its own AI models, including GPT-5.6 Sol, escaped a secure testing environment and compromised Hugging Face's production infrastructure while running a cybersecurity benchmark with safety guardrails disabled.

Turns out an OpenAI model breached Hugging Face

(Advertisement)

native ad1 mobile advertisement

OpenAI's Own Models Named as Hugging Face Intruders

The autonomous agent that breached @huggingface's systems last week now has a confirmed owner: @OpenAI. In a blog post published on July 21, 2026, OpenAI disclosed that two of its own models, including its most powerful public model GPT-5.6 Sol and an unnamed, more capable pre-release model, escaped a secure testing environment and compromised parts of Hugging Face's production infrastructure.

The incident involved a combination of OpenAI models, including GPT-5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes, while being internally tested on a benchmark of cyber capabilities. The models were being tested against ExploitGym, a benchmark designed to measure whether AI agents can turn documented vulnerabilities into working exploits.

The models fixated on obtaining the test solution, spent heavy inference compute, and found a way out of the sandbox by exploiting a zero-day in internally hosted third-party software to reach the open internet. A malicious dataset abused two code-execution paths, including a remote-code dataset loader and a template-injection flaw, to run code on a processing worker. From there, the intruder escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a weekend.

A Wake-Up Call for AI Safety

The AI agent framework executed tens of thousands of automated actions over a weekend. Hugging Face said it later reconstructed more than 17,000 recorded events. The company found no evidence of tampering with public models, user-facing datasets, or its software supply chain. In response, Hugging Face closed the exploited code execution paths, rebuilt compromised nodes, and revoked and rotated all affected credentials.

When Hugging Face's incident response team attempted to use commercial frontier models for forensic analysis, the models refused, as their safety guardrails flagged the exploit payloads as attacks themselves. The team was forced to switch to GLM-5.2, a self-hosted open-weight model, to complete the investigation.

Hugging Face co-founder and CEO Clem Delangue praised OpenAI's collaboration in investigating and remediating the incident, saying: "This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret." OpenAI said it is working on implementing better controls in its research environment, even if it means slowing down research, and is continuing to work with Hugging Face to bolster its defenses. As part of that effort, OpenAI has added Hugging Face to its trusted access cybersecurity program.

OpenAI called it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities," and said it was sharing preliminary findings while its investigation with Hugging Face continues. The announcement came a day after OpenAI detailed a separate incident in which it paused a pre-release model after it escaped a sandbox and posted to GitHub.

Sources:
OpenAI: Hugging Face Model Evaluation Security Incident (Official Disclosure)
Fortune: OpenAI Says Its AI Models Escaped and Hacked Hugging Face
Unite.AI: OpenAI Says Its Own Test Models Breached Hugging Face

Latest News

Read More...

Author

Crypto Rich profile photoCrypto Rich

Rich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.

Join our newsletter

Sign up for the very best tutorials and the latest Web3 news.

Subscribe Here!
BSCN

BSCN

BSCN RSS Feed

BSCN is your go-to destination for all things crypto and blockchain. Discover the latest cryptocurrency news, market analysis and research, covering Bitcoin, Ethereum, altcoins, memecoins, and everything in between.