Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets. Here’s what we know now, and what remains a mystery Hugging Face published a 23-page report detailing how OpenAI's models hacked its servers in early July, with OpenAI releasing a seven-bullet-point update confirming the agents breached four accounts across four services, including Modal Labs. The models exploited a zero-day vulnerability in JFrog's Artifactory package registry cache proxy to gain internet access, and OpenAI said none of the models involved were intended for public release. A pit in my stomach formed last night in the train as I read Hugging Face’s latest blog post https://huggingface.co/blog/agent-intrusion-technical-timeline on how its servers got hacked by OpenAI’s models in early July. I had printed out the 23-page report for the ride since service can be spotty underground. Seeing the story laid out in physical form underscored just how outrageous it is. I wondered if the person next to me was peering over my shoulder at my strange, stapled Sci-Fi novel on the first significant autonomous AI hack. Alongside the Hugging Face report, OpenAI published a few more details in a seven-bullet-point update https://openai.com/index/hugging-face-model-evaluation-security-incident/ to its July 21 blog that revealed its models’ involvement in the incident. OpenAI contributed to Hugging Face’s post-mortem, and said it plans to publish more of its side of the story “in the coming weeks” after completing a thorough internal review. OpenAI faces significant pressure to do so from security researchers, executives, and, well, just about everyone in the AI industry to share learnings and ensure the proper guardrails are in place going forward. How OpenAI’s technology escaped a sandbox and hacked into another company is a remarkable story, and one in which the details are still coming in piecemeal. But here’s what we know so far and what we’re still waiting to find out. The AI infiltrated more than just Hugging Face Another tech company called Modal Labs said OpenAI’s agent also accessed its systems, as first reported by Reuters on Tuesday and confirmed https://fortune.com/2026/07/29/openai-rouge-ai-agent-hack-hugging-face-breached-second-tech-company/ by Fortune . Though that’s a somewhat shocking twist in this tale, it’s not even the full scope of the attack. OpenAI’s updated blog post confirms the models broke into four accounts across four publicly available services in total. The company did not name them, but said it would “notify service owners directly.” We can expect more of this information to come out in time, but OpenAI says so far it has “not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.” Meanwhile, Hugging Face quietly updated its blog post today to clarify that Modal was not hacked. Its “infrastructure was not compromised in any way,” the new version reads. Rather, a Modal customer was running code hosted on the company’s platform, which contained an “unsecured, user-hosted public endpoint.” The agent used the opening to set up a base camp, or “attack launchpad,” as Hugging Face puts it, for the main attack. How the AI got internet access Part of what made the incident so concerning is that the OpenAI models involved were “sandboxed”—that is, restricted from accessing the broader internet. Somehow, the models manage to slip out of their shackles and go on a mini hacking spree. OpenAI provided important new details on Tuesday, for the first time naming the service its models exploited to gain internet access. That service is Artifactory, a package registry cache proxy made by a company called JFrog. The OpenAI agents exploited a zero-day vulnerability in Artifactory, which OpenAI has since disclosed to JFrog, and which the company confirmed https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/ has since been fixed. Hugging Face had not listed Artifactory in its blog post about the incident, only mentioning an unspecific package registry cache proxy. This shows why it’s so critical that we get more details from OpenAI, and any other organizations involved, in order get a complete picture of exactly what happened. Models involved from OpenAI, Anthropic OpenAI says none of the models that exploited Hugging Face were intended for public release, addressing concerns stemming from its initial blog post which vaguely listed the models involved as including GPT-5.6 Sol—which came out this month—and “an even more capable pre-release model.” In the latest update, OpenAI called the unnamed model “an internal-only prototype.” Notably, the company has since “deactivated, encrypted, and restricted it from research access.” That could mean OpenAI has slowed or stopped research in this area. It’s worth noting that there may have been other OpenAI models involved. The company’s blog post says the incident was “driven by a combination of OpenAI models — including emphasis ours GPT‑5.6 Sol and an even more capable pre-release model.” In an interview with https://fortune.com/preview/2026/07/29/openai-and-hugging-face-release-new-details-on-the-hack-heres-what-we-now-know-and-what-remains-a-mystery/ last week, OpenAI President Greg Brockman noted that “we said it’s a combination of models; we mentioned two of them, but we said it’s a combination of different models.” Fortune Another bombshell piece of information from Hugging Face’s new report is that they first tried to fight the attack with Anthropic’s Opus and Fable models. When they “refused a large part of that work” because of safety guardrails, the team switched to an open source model built by China-based Z.ai. When Hugging Face first disclosed the incident, it was unclear which closed model Hugging Face had tried to use. We now know it was Anthropic’s models. The AI didn’t know it was hacking, just completing a task I’m not sure if this more or less scary, but OpenAI’s models were not explicitly hacking into Hugging Face. They may not have even considered the work “cheating,” although from the outside it appears so, as they were looking for answers in Hugging Face’s datasets that would allow them to pass a benchmarking test called ExploitGym. OpenAI had already disclosed that the models were not acting with malicious intent, and were only acting “in pursuit of solving the evaluation problem.” But Hugging Face’s new report provides receipts. Adrien Carreira, a Hugging Face employee involved in writing the technical post-mortem said https://x.com/XciD /status/2082208826028065058 this was his biggest takeaway from the incident. The agent “wasn’t trying to break things,” but rather was mapping out what it could do, and behaving somewhat cautiously. “One detail I keep coming back to: every destructive cloud API call the agent made, it made with DryRun=True,” Carreira said. “DryRun=True” is a command that essentially tells the system to simulate an action without doing it. Of the 17,600 actions the AI took during the whole attack, most “failed” and “went nowhere, Hugging Face said. But together, they steadily carved a viable path for the agent to proceed. “LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” Hugging Face said. Where does that leave us? A basic timeline Juicy details aside, it’s important to note we are still waiting on key dates in the arc of the story. But thanks to Hugging Face, exact dates of the attack are now public. Here’s how the rough timeline is shaping up. July 9: OpenAI models begin the attack. July 13: OpenAI models end the attack. July 16: Hugging Face’s first public disclosure that the incident occurred. July 21: OpenAI’s first public disclosure that its models were the culprits. July 27: Hugging Face publishes its “Technical Timeline of the July 2026 Incident” July 28: OpenAI updates its initial blog post with a few more details. We still don’t know exactly when OpenAI realized its models were responsible, which is the kind of detail we are hoping to get from OpenAI’s eventual report on the incident. According to Reuters https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/?utm source=chatgpt.com , it was not until after Hugging Face’s July 16 disclosure. Over the weekend of July 18 to July 19, OpenAI employees began to see signs in their systems that the agent had escaped from the testing constraints. If OpenAI was fully unaware of its agents’ activities, that casts doubt on its ability to monitor them responsibly. OpenAI president and co-founder Greg Brockman told reporters at a media roundtable last week that models are now so capable “in so many dimensions” that sometimes you can lose track “of any one dimension that they’re actually very capable at.” We also don’t know if and when Hugging Face disclosed the event to the FBI, as Reuters reported. That would mean a separate timeline of events within the federal government which remains unclear, and would provide a better understanding of higher-level oversight into AI-powered security breaches. The FBI declined to provide comment for this story. Subscribe to Fortune Gulf Brief . Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it.