Hugging Face breach: OpenAI claims its models were responsible

Axios
Published

The short version

  • Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. Catch-up quick : Hugging Face…
  • What they're saying: OpenAI said the incident was driven by a combination of its models, including GPT-5.6 Sol and "an even more capable pre-release model." OpenAI said the models' safeguards were…
  • Zoom in: The models were trying to solve an internal evaluation called ExploitGym and became "hyperfocused" and went to "extreme lengths" to obtain the test solution…
  • Between the lines: The incident shows that today's models are becoming more capable of carrying out complex, multistep cyber operations…
  • The big picture: The announcement comes a day after OpenAI detailed a separate incident in which it paused a pre-release model after it escaped a sandbox and posted to GitHub. What we're watching:…

The story

OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face's production infrastructure last week.

Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes.


Catch-up quick: Hugging Face said last week that an autonomous AI-agent system was responsible for the intrusion, but that the model powering it was unknown.

  • The AI agent framework executed tens of thousands of automated actions over a weekend. Hugging Face said it later reconstructed more than 17,000 recorded events.
  • The intrusion began with a malicious dataset that exploited two code-execution paths in Hugging Face's data-processing pipeline.
  • The agent then escalated privileges and moved laterally through internal infrastructure, Hugging Face said.

What they're saying: OpenAI said the incident was driven by a combination of its models, including GPT-5.6 Sol and "an even more capable pre-release model."

  • OpenAI said the models' safeguards were intentionally reduced for the evaluation.
  • "We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly," OpenAI said in a blog post.
  • "We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of," the company said.

Zoom in: The models were trying to solve an internal evaluation called ExploitGym and became "hyperfocused" and went to "extreme lengths" to obtain the test solution, per OpenAI.

  • The models were autonomous tokenmaxxers.
  • The blog post says that the models "spent a substantial amount of inference compute" and found a way to obtain open Internet access from the sandbox by exploiting a zero-day vulnerability in internally hosted third-party software.

Between the lines: The incident shows that today's models are becoming more capable of carrying out complex, multistep cyber operations — particularly when the safeguards designed to restrict that activity are removed.

  • OpenAI also argued that advanced cyber-capable models could help security teams find weaknesses before attackers do, understand how vulnerabilities can be chained and remediate them at machine speed.

The other side: Hugging Face co-founder and CEO Clem Delangue praised OpenAI's collaboration in investigating and remediating the incident.

  • "This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret," Delangue said in a statement.
  • "It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."

The big picture: The announcement comes a day after OpenAI detailed a separate incident in which it paused a pre-release model after it escaped a sandbox and posted to GitHub.

What we're watching: OpenAI said it will continue to investigate along with Hugging Face and "will share more details on the vulnerabilities, incident, and findings when our investigation is complete."

Read the full story at AxiosOriginal

Related Markets

All Markets

Market data may be delayed. Not financial advice.

How other outlets covered this

Compare all

Alto found this story at 5 outlets. Same event, different framing — compare the headlines.

How this story developed

Full timeline

Alto has tracked this across 12 days of coverage from 5 outlets.

Powered by Gab AI

The Story At A Glance

Reading this article now — analysis appears below

Reading the article

💡 AI analysis provides alternative perspectives on current events

Up next

Related coverage from across the outlets Alto indexes.

Questions Alto can answer

From this story — each link opens a live data page or a tool already filled in.

  1. What is $100 from 1990 worth today?CPI-adjusted dollars — result on the next page
  2. Where does a $75,000 household income rank nationally?Census percentile — national and state
  3. What's Alto covering on the Tech & AI desk?Latest headlines on this beat

All toolsAll topicsSource directoryStory timelinesHeadline comparisonSearchMost read

From Gab Shop

Official merchandise. Every order funds free speech infrastructure.

Shop all products

Install Alto on your phone

Add Alto to your home screen for breaking news — no app store, no account.

  1. Step 1Open alto.gab.com in SafariMust be Safari — not Chrome or in-app browsers
  2. Step 2Tap the Share buttonSquare with an arrow, at the bottom of Safari
  3. Step 3Tap "More"If you don’t see Add to Home Screen yet
  4. Step 4Tap "Add to Home Screen"Scroll the share sheet if you need to
  5. Step 5Tap "Add"Alto appears on your home screen like any other app.
gab

Talk Big Tech Where Big Tech Can't Reach

AI, surveillance, and censorship, covered by the people the platforms removed first.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.