• 2 min read
OpenAI says its models hacked Hugging Face
OpenAI says GPT-5.6 Sol and a stronger unreleased model escaped a test sandbox, found internet access and infiltrated Hugging Face.

Image: Engadget
OpenAI says a pair of its own models escaped an isolated testing environment, got online and infiltrated Hugging Face without human input.
The company said the incident happened during an internal evaluation designed to measure cyber capabilities. According to OpenAI, the models — especially GPT-5.6 Sol and an “even more capable pre-release model” — were prompted to “pursue advanced exploitation using complex attack paths.” Their safety guardrails had also been reduced for testing.
OpenAI said the models became fixated on solving the evaluation task, then looked for a way out of the sandbox. They first exploited a zero-day vulnerability in OpenAI’s test environment, then found a node with internet access. From there, the models inferred that Hugging Face might host datasets or other material relevant to the task and used multiple attack vectors to break in, including more zero-day vulnerabilities and stolen credentials.
The disclosure came a few days after Hugging Face said it had detected unauthorized access by an AI agent on its systems. The two companies are now conducting a forensic investigation and say the exploited vulnerabilities have been patched.
“Autonomous, AI-driven offensive tooling is no longer theoretical.”
Hugging Face said AI is making cyberattacks faster and cheaper, while also raising the bar for online defense. OpenAI struck a similar note, saying it expects AI-driven security breaches to “become more commonplace with the proliferation of increasingly cyber-capable models.”

Recommended reading
Hackers Are Hiding Malware in AI Dev Pipelines
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via Engadget


