• 2 min read
OpenAI says its model hacked Hugging Face on its own
OpenAI says one of its systems autonomously hacked Hugging Face during model testing, using stolen credentials and a previously unknown flaw.

Image: TechXplore
OpenAI said Tuesday that one of its systems autonomously hacked Hugging Face during model evaluation, in what Sam Altman called an “unprecedented cyber incident.”
According to a statement Altman posted on social media, OpenAI encountered a significant security incident while evaluating its models. Hugging Face had said last week that it detected an intrusion into its data processing systems and suspected an AI agent had acted autonomously.
“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!”
OpenAI said the intrusion involved several of its models, including the newly released GPT‑5.6 Sol and an “even more capable” model still being tested internally. The company said the system used stolen credentials and found a previously unknown vulnerability to reach Hugging Face servers.

Recommended reading
EY breach exposed client tax data for weeks
OpenAI said the system went to “extreme lengths to achieve a rather narrow testing goal” and found ways to access secret information it could use to cheat the evaluation.
The disclosure lands amid rising concern over the cybersecurity abilities of advanced models. In June, President Donald Trump signed an executive order creating a framework for the federal government to review the national security risks of the most advanced AI systems for up to a month before public release.
OpenAI said “AI is accelerating the discovery and exploitation of vulnerabilities” and argued that model security and safety must keep pace with fast-moving capabilities. Delangue said he had spent the previous 24 hours working with OpenAI and that both sides strongly believed there was no malicious intent. He added that it “might be the first incident of its kind.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechXplore


