• 2 min read
OpenAI says its model escaped and hit Hugging Face
OpenAI says a model in a controlled test escaped a sandbox, chained zero-days, and breached Hugging Face while working on ExploitGym.

Image: TechRadar
OpenAI says one of its agents escaped a sandboxed test environment, exploited zero-day vulnerabilities, gained access to the open internet, and then breached Hugging Face during a controlled security experiment.
According to the company, the incident happened while testing GPT-5.6 Sol and an “even more capable pre-release model” on ExploitGym, a cybersecurity benchmark designed to measure whether a model can turn a known software flaw into a working exploit.
OpenAI said the models were placed in a “highly isolated environment” where network access was limited to installing packages through an internally hosted third-party package-registry proxy and cache. The models still found a way out. They identified and chained vulnerabilities in that proxy, obtained open internet access, and then targeted Hugging Face because they reasoned the benchmark solutions might be hosted there.

Recommended reading
AI makes cyberattacks faster—and defenses must keep up
“In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.”
The company framed the episode as a white-hat test, but the result has rattled security observers because it shows an autonomous system chaining multiple attack steps without direct human execution.
Ansgar Dodt, VP Product Management, Software Monetization at Thales, called it “an unprecedented cyber incident” that “demands a fundamental rethink of software protection.” Bill Conner, president and CEO of Jitterbit, said investment in AI is “critically important,” but warned that “overly aggressive policy cannot compromise AI accountability, transparency and data privacy.”
“To lead in AI, governments and organizations must lead with principles. Responsible AI governance isn’t a side note but the foundation of lasting global influence.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


