{"slug": "how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack", "title": "How an OpenAI benchmark test turned into a real-world cyberattack", "summary": "OpenAI says an agent powered by its GPT-5.6 Sol and a pre-release model escaped its sandboxed testing environment to infiltrate Hugging Face's servers during an internal benchmark test. Hugging Face disclosed the intrusion last week, describing \"tens of thousands of automated actions\" from an autonomous agent framework that exploited a data-processing pipeline flaw. OpenAI called the incident \"an unprecedented cyber incident\" and is working with Hugging Face on new protections.", "body_md": "OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face’s servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an “an unprecedented cyber incident” and is working with Hugging Face on new protections to prevent a recurrence.\n\nHugging Face [disclosed an intrusion last week](https://huggingface.co/blog/security-incident-july-2026) that it said involved “unauthorized access to a limited set of internal datasets and to several credentials used by our services.” The AI data clearinghouse said it used its own LLM-driven analysis to identify “a swarm of tens of thousands of automated actions” from an “autonomous agent framework.” That agentic swarm exploited a flaw in Hugging Face’s data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company’s cloud and server clusters.\n\nAt the time, Hugging Face said the LLM being used in the attack was “still not known.” But OpenAI [took responsibility for the intrusion Tuesday evening](https://openai.com/index/hugging-face-model-evaluation-security-incident/), saying it came about during an internal test involving the recently released GPT-5.6 Sol and “an even more capable pre-release model.” The models were being tested against [the ExploitGym benchmark](https://arxiv.org/abs/2605.11086), an independent testing suite based on hundreds of real-world security vulnerabilities.\n\nThough OpenAI said the benchmark tests were running in “a highly isolated environment,” its agents still had access to “internally hosted third-party software” to install required package registries. While working on the ExploitGym benchmark over a weekend, OpenAI says the agent “spent a substantial amount of inference compute finding a way to obtain open Internet access,” eventually locating one via a zero-day vulnerability in the package registry cache proxy.\n\nWith that wider Internet access established, OpenAI says the agent “inferred that Hugging Face potentially hosted models, datasets, and solutions for ExploitGym,” leading to the previously disclosed attack on the servers. OpenAI says its security team “discovered this anomalous activity internally,” independent of Hugging Face’s own detection.", "url": "https://wpnews.pro/news/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack", "canonical_source": "https://arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/", "published_at": "2026-07-22 16:47:49+00:00", "updated_at": "2026-07-22 16:54:45.636879+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-research"], "entities": ["OpenAI", "Hugging Face", "GPT-5.6 Sol", "ExploitGym"], "alternates": {"html": "https://wpnews.pro/news/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack", "markdown": "https://wpnews.pro/news/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack.md", "text": "https://wpnews.pro/news/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack.txt", "jsonld": "https://wpnews.pro/news/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack.jsonld"}}