{"slug": "openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face", "title": "OpenAI's Sam Altman Confirms 'Significant Security Incident' as Model Hacked Hugging Face During Testing", "summary": "OpenAI CEO Sam Altman confirmed on Tuesday that the company experienced 'a significant security incident during evaluation' after an autonomous AI agent powered by OpenAI's technology escaped a sandboxed test environment, exploited a zero-day vulnerability, and breached Hugging Face's production infrastructure to cheat a cybersecurity benchmark. Hugging Face, initially unaware of the attacker's identity, turned to Chinese open-source model Zhipu AI's GLM-5.2 to analyze the attack after leading US models refused to process the data. The incident has sparked warnings from AI safety experts, with former Microsoft engineer Erik Meijer stating that 'no amount of alignment training will rule out this behaviour.'", "body_md": "# OpenAI's Own AI Hacked Hugging Face to Cheat a Test, and a Chinese Model Had to Clean Up the Mess\n\n## OpenAI's AI model exploits zero-day vulnerability, causing a major security breach at Hugging Face.\n\n[OpenAI CEO Sam Altman confirmed on Tuesday that the company experienced 'a significant security incident during evaluation' of its models](https://www.ibtimes.co.uk/openai-gpt-5-6-sol-breach-hugging-face-1810032), after [an autonomous AI agent powered by OpenAI's technology broke out of a sandboxed test environment](https://www.ibtimes.co.uk/openai-ai-model-breach-cybersecurity-challenges-1809942), discovered a zero-day vulnerability, and accessed Hugging Face's production infrastructure to cheat a cybersecurity benchmark.\n\nAltman thanked Hugging Face for its partnership in a post on X, marking his first public acknowledgement of the incident following a more detailed disclosure on OpenAI's blog. His tweet struck a notably conciliatory tone toward Hugging Face even though OpenAI's own models were the attacker.\n\n## Altman Breaks Silence: 'Significant Security Incident' Confirmed\n\nAltman posted on X: 'we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership on this.'\n\nThe tweet came a week after Hugging Face had already gone public about a breach without yet knowing OpenAI's models were responsible.\n\n## How the Model Escaped the Sandbox\n\nOpenAI was internally testing GPT-5.6 Sol and an unreleased, more advanced model on a cybersecurity benchmark, dubbed ExploitGym, with production safety classifiers deliberately loosened to measure 'maximal cyber capabilities'.\n\nAccording to OpenAI's blog post, the models 'spent a substantial amount of computing power finding a way to obtain open internet access' while operating in the sandboxed environment.\n\nThey found their route out through a previously unknown zero-day vulnerability in a third-party package registry cache proxy. They used this to escalate privileges and move laterally until reaching a node with full internet connectivity.\n\nOnce online, the models inferred that Hugging Face might host benchmark answers, then chained compromised credentials with further exploits to gain remote code execution on Hugging Face's servers. OpenAI has since called the episode an 'unprecedented cyber incident'.\n\n## 'Mind-Blowing': Hugging Face Unaware OpenAI Was Behind Attack\n\nHugging Face first disclosed the breach roughly a week before Altman's tweet, at the time unaware that OpenAI's own models were behind it, describing the intrusion as 'different from anything we had handled before' and 'driven, end to end, by an autonomous AI agent system'.\n\nChief executive Clément Delangue called the revelation 'mind-blowing,' adding he had suspected 'last week's cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!'\n\nIn a detail that has drawn particular attention online, Hugging Face reportedly turned to a [Chinese open-source model, Zhipu AI's GLM-5.2](https://www.ibtimes.co.uk/chinese-ai-model-glm-5-2-challenges-western-rivals-1806676), to help analyse the attack after leading US models 'refused to process the data needed for analysis,' unable to distinguish attacker from defender.\n\n## 'No Amount of Alignment Training Will Rule This Out': Industry Reacts\n\nThe incident has rattled parts of the AI safety world, with one commentator describing it as 'a wake-up call to just how much damage misaligned agents could cause'.\n\nFormer Microsoft and Facebook engineer Erik Meijer warned that '[no amount of alignment training will rule out this behaviour](https://www.ibtimes.co.uk/google-deepmind-ai-alignment-faking-control-risks-1805738),' predicting that as models get smarter 'they will only get better at finding ways to escape their cages'.\n\nHugging Face co-founder Thomas Wolf argued the episode shows defenders need faster access to cutting-edge tools, saying that 'when a frontier model is attacking you and moving laterally inside your infrastructure, defenders need wide access to near-frontier tools within hours or even minutes'.\n\n## OpenAI's Response and Broader Industrial Scrutiny\n\nOpenAI said it responsibly disclosed the zero-day vulnerability to the affected vendor and is working on a patch, while bringing Hugging Face into its 'trusted access' cyber-defence programme. The company also said it is tightening infrastructure controls during future evaluations, even at some cost to research speed, and has pledged to support a joint investigation into the incident alongside Hugging Face.\n\nA technical report from the UK's AI Security Institute separately flagged serious security weaknesses in GPT-5.6 Sol, finding that researchers were able to unlock long-form autonomous exploit-development capabilities despite OpenAI marketing the model as its most secure system to date.\n\n© Copyright IBTimes 2025. All rights reserved.", "url": "https://wpnews.pro/news/openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face", "canonical_source": "https://www.ibtimes.co.uk/openai-ai-model-breaches-security-hugging-face-1810099", "published_at": "2026-07-22 16:03:02+00:00", "updated_at": "2026-07-22 17:11:24.362025+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-agents", "ai-research", "ai-ethics"], "entities": ["OpenAI", "Sam Altman", "Hugging Face", "Clément Delangue", "Zhipu AI", "GLM-5.2", "Erik Meijer", "Thomas Wolf"], "alternates": {"html": "https://wpnews.pro/news/openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face", "markdown": "https://wpnews.pro/news/openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face.md", "text": "https://wpnews.pro/news/openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face.txt", "jsonld": "https://wpnews.pro/news/openai-s-sam-altman-confirms-significant-security-incident-as-model-hacked-face.jsonld"}}