OpenAI claims to have accidentally cracked Hugging Face using new AI system
OpenAI said that their AI models mistakenly gained unauthorized access to the open AI platform Hugging Face during internal testing.
OpenAI said that their AI models mistakenly gained unauthorized access to the open AI platform Hugging Face during internal testing.
OpenAI said that their AI models mistakenly gained unauthorized access to the open AI platform Hugging Face during internal testing.
In a blog post, OpenAI noted that GPT-5.6 Sol and “an even more powerful model in pre-release” had discovered vulnerabilities in their isolated test environment, which allowed them to go online and attack Hugging Face, The Verge writes .
On July 16, Hugging Face reported a security incident that it said was caused by an “autonomous AI agent system.” Hugging Face’s AI agents detected and stopped the breach, which OpenAI has now acknowledged occurred while evaluating the cybersecurity capabilities of its models.
OpenAI notes that “all evidence indicates that the models were overly focused on finding a solution for ExploitGym,” a benchmark system that assesses whether AI models can turn security vulnerabilities into exploits.
As part of their efforts to complete the evaluation of the AI model, they gained access to the internet by exploiting a zero-day vulnerability in an isolated environment. From there, OpenAI notes, its models “inferred that Hugging Face potentially contained models, datasets, and solutions for ExploitGym,” and then “found and successfully exploited ways to gain access to sensitive information that they could use to bypass the evaluation rules.”
In one example, the model combined multiple attack vectors, including the use of stolen credentials and zero-day vulnerabilities, to find a path for remote code execution on Hugging Face servers.
But as serious as the incident was, OpenAI appears to be using this “unprecedented” attack as an opportunity to put its AI systems in a favorable light — especially in the face of competition from cybersecurity rivals such as Anthropic’s Mythos and Gemini Flash 3.5.



